On March 31, 2026, the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages ...
Axios 1.14.1 and 0.30.4 injected malicious plain-crypto-js@4.2.1 after npm compromise on March 31, 2026, deploying ...
Hackers hijacked the npm account of the Axios package, a JavaScript HTTP client with 100M+ weekly downloads, to deliver ...
Google links Axios npm supply chain attack to UNC1069 after trojanized versions 1.14.1 and 0.30.4 spread WAVESHAPER.V2, ...
A North Korea-nexus threat actor compromised the widely used axios npm package, delivering a cross-platform remote access ...
The maintainer account for the axios package on npm was compromised to inject a remote access trojan for Windows, macOS, and ...
Some classics deserve to be retired.
OpenClaw's Node for VS Code extension proved it can support a real local file-based workflow, but on Windows the experience still feels more like early infrastructure than finished tooling.
An attacker compromised the npm account of a lead Axios maintainer on March 30, and used it to publish two malicious versions ...
VRM MCP Proxy VRM Agent Host (vrmah) と VOICEVOX を MCP (Model Context Protocol) 経由で制御する統合プロキシサーバー。 主に Claude Code CLI / VSCode 拡張 / Codex CLI のいずれの環境でも同一の mcp_server.py で動作します。
Scripts # Development npm run dev # Start development environment npm run build # Build all modules npm run test# Run all tests npm run lint # Run linting npm run type-check # Type checking# Docker ...
Two versions of the widely used JavaScript library axios were maliciously published on npm on March 31, 2026. A hijacked ...