Most likely, a maintainer's GitHub and npm accounts are compromised as these issues are getting deleted. I have also reported this as a vulnerability, so that a CVE can be generated.
Hackers infiltrated Axios maintainers using fake Slack channels and Teams calls, then published infected packages.
A critical supply chain attack has compromised the popular JavaScript library axios, leading to developers unknowingly ...
A supply-chain attack backdoored versions of Axios, a popular JavaScript library that's present in many different software ...
The breach highlights how North Korean hackers are using elaborate and seemingly real virtual business meetings, powered by ...