EVENTS / webinar

Live Briefing: Lessons from the axios npm attack

npm axios attack: What happened and how to protect your supply chain

  • Thu, Apr 2 · 3:30PM UTC

Things you'll learn

  • How the attack worked – from credential compromise to RAT deployment
  • The staging techniques that helped the payload avoid early detection
  • Defenses you can put in place today, including dependency pinning, age-based package policies, and threat intelligence integration

Speakers

Nigel Douglas
Nigel Douglas
Head of Developer RelationsCloudsmith
Jenn Gile
Jenn Gile
FounderOpenSourceMalware

Summary

LIVE BRIEFING: This week, axios - the JavaScript HTTP client with over 100 million weekly npm downloads - was compromised in a supply chain attack. A malicious actor used a compromised maintainer account to inject a remote access trojan into two active release branches.

Join our Head of Developer Relations, Nigel Douglas and Founder of OpenSourceMalware, Jenn Gile for a 30-minute live breakdown of the attack and practical steps any engineering team can take to reduce their exposure to this type of threat.