<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>RAT Articles &amp; Updates - berightnews</title>
	<atom:link href="https://berightnews.com/tag/rat/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>Latest International News &#38; Sports Updates</description>
	<lastBuildDate>Tue, 31 Mar 2026 12:05:40 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://berightnews.com/wp-content/uploads/2026/02/cropped-ChatGPT-Image-6-февр.-2026-г.-17_07_32-32x32.png</url>
	<title>RAT Articles &amp; Updates - berightnews</title>
	<link></link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Axios: Malicious Versions of  Discovered on npm</title>
		<link>https://berightnews.com/2026/03/31/axios-malicious-versions-of-discovered-on-npm/</link>
		
		<dc:creator><![CDATA[newsroom]]></dc:creator>
		<pubDate>Tue, 31 Mar 2026 12:05:40 +0000</pubDate>
				<category><![CDATA[Trending]]></category>
		<category><![CDATA[axios]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[JavaScript]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[npm]]></category>
		<category><![CDATA[RAT]]></category>
		<category><![CDATA[Remote Access Trojan]]></category>
		<category><![CDATA[software supply chain]]></category>
		<category><![CDATA[StepSecurity]]></category>
		<guid isPermaLink="false">https://berightnews.com/2026/03/31/axios-malicious-versions-of-discovered-on-npm/</guid>

					<description><![CDATA[<p>Two malicious versions of axios have been published on npm, exploiting compromised credentials and targeting multiple operating systems.</p>
<p>The post <a href="https://berightnews.com/2026/03/31/axios-malicious-versions-of-discovered-on-npm/">Axios: Malicious Versions of  Discovered on npm</a> appeared first on <a href="https://berightnews.com">berightnews</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h2>Key moments</h2>
<p>In a significant security breach, two malicious versions of <strong>axios</strong>, a widely used JavaScript HTTP client library, were published on npm on March 31, 2026. The versions, v1.14.1 and v0.30.4, were live for approximately 2 hours 53 minutes and 2 hours 15 minutes, respectively, before being removed shortly after discovery.</p>
<p>The attack was executed using compromised credentials of a lead axios maintainer, who had their account email changed to an anonymous ProtonMail address. This breach allowed the attacker to inject a malicious package, <strong>plain-crypto-js@4.2.1</strong>, as a dependency, which was designed to evade detection by appearing legitimate.</p>
<p>According to reports, the attack was pre-staged for roughly 18 hours before the malicious versions were published. During this time, the attacker prepared a cross-platform Remote Access Trojan (RAT) targeting macOS, Windows, and Linux environments. The RAT dropper executes a postinstall script that contacts a command-and-control server, potentially compromising user systems.</p>
<p>With over <strong>100 million weekly downloads</strong>, axios is a critical component in many software projects, with approximately <strong>80%</strong> of cloud and code environments utilizing it. The implications of this attack are severe, as it has been observed that execution of the malicious code occurred in <strong>3%</strong> of affected environments.</p>
<p>The attack was detected by StepSecurity AI Package Analyst and StepSecurity Harden-Runner, highlighting the importance of security tools in identifying such threats. &#8220;This is among the most operationally sophisticated supply chain attacks ever documented against a top-10 npm package,&#8221; a security expert noted, emphasizing the attack&#8217;s complexity and potential impact.</p>
<p>Organizations are now being urged to audit their environments for any potential execution of these malicious versions. &#8220;There are zero lines of malicious code inside axios itself, and that&#8217;s exactly what makes this attack so dangerous,&#8221; another expert stated, underlining the challenge of securing software supply chains.</p>
<p>As the situation develops, further investigations are underway to assess the full extent of the compromise and to implement measures to prevent similar incidents in the future. Details remain unconfirmed regarding the total number of affected users and systems, but the urgency for heightened security measures is clear.</p>
<p>The post <a href="https://berightnews.com/2026/03/31/axios-malicious-versions-of-discovered-on-npm/">Axios: Malicious Versions of  Discovered on npm</a> appeared first on <a href="https://berightnews.com">berightnews</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
