Brennenstuhl on Security · May 15, 2026
Dependency Updates: latest Is Not a Security Strategy
0Sign in to vote or save
This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.
On March 31, 2026, North Korean state actors compromised Axios , an npm package with over 70 million weekly downloads. Any project declaring axios@^1.14.0 connected to attacker C2 infrastructure the next time npm update ran. Six weeks later, a self-propagating worm hit 42 TanStack packages . It reached Mistral AI, UiPath, and OpenAI within hours. It also carried valid SLSA provenance attestations,…
Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.