這幾天建議大家先別安裝、更新 js 模組 😂
Axios 中招,這波影響應該誇張大...
作者帳號被盜,模組被更新成塞了惡意程式碼的版本...
Replying to @feross and @SocketSecurity
UPDATE in case you missed it earlier: This is bigger than initially reported. Both [email protected] AND [email protected] were compromised – the attacker poisoned the 1.x and 0.x branches within 39 minutes of each other, maximizing blast radius across projects using caret ranges.



