<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Axios npm Supply Chain Attack</title>
    <link>https://ramimac.me/axios/</link>
    <description>Updates on the Axios npm supply chain attack. Compromised maintainer account, credential stealer via plain-crypto-js dependency.</description>
    <language>en-us</language>
    <atom:link href="https://ramimac.me/axios/feed.xml" rel="self" type="application/rss+xml"/>
    <lastBuildDate>Sun, 06 Apr 2026 17:30:00 +0000</lastBuildDate>

    <item>
      <title>MGC Copycat Attack</title>
      <link>https://ramimac.me/axios/#phase-2</link>
      <guid isPermaLink="true">https://ramimac.me/axios/#phase-2</guid>
      <pubDate>Thu, 02 Apr 2026 06:12:00 +0000</pubDate>
      <description>Copycat attack on module-generate-cli (mgc) package via compromised admondtamang account. Similar techniques to axios attack but no confirmed relationship to DPRK actors.</description>
    </item>

    <item>
      <title>Axios npm Compromise</title>
      <link>https://ramimac.me/axios/#phase-1</link>
      <guid isPermaLink="true">https://ramimac.me/axios/#phase-1</guid>
      <pubDate>Tue, 31 Mar 2026 00:21:58 +0000</pubDate>
      <description>Compromised jasonsaayman npm account publishes axios@1.14.1 and axios@0.30.4 with injected plain-crypto-js dependency. Multi-platform credential stealer targeting Windows, macOS, and Linux.</description>
    </item>

  </channel>
</rss>
