🚀 New Releases

Axios 1.14.1: The NPM Hijack That Stole Your SSH Keys in Seconds

Ever wonder if that quick 'npm install axios@latest' just handed your AWS keys to a stranger? On March 31, 2026, it did—for 40 million weekly users.

Timeline diagram of axios@1.14.1 supply chain attack from account takeover to RAT deployment

⚡ Key Takeaways

  • [email protected] hijack used account takeover and fake dep to drop RATs stealing creds in seconds. 𝕏
  • Standard tools like npm audit lagged 12+ hours; need pre-install behavioral checks. 𝕏
  • AI dev agents explode risk—tools like Ward target this, but watch for vendor upsells. 𝕏
Published by

DevTools Feed

Ship faster. Build smarter.

Worth sharing?

Get the best Developer Tools stories of the week in your inbox — no noise, no spam.

Originally reported by dev.to

Stay in the loop

The week's most important stories from DevTools Feed, delivered once a week.