The recent cybersecurity incident involving the popular JavaScript library Axios highlights significant risks in software supply chains. Here are key points from Microsoft's guidance to mitigate this npm (Node Package Manager) supply chain compromise:
-
Affected Versions:
- Roll back Axios deployments to version 0.30.3 or 1.14.0 immediately.
-
Credential Rotation:
- Rotate any secrets or credentials exposed on compromised systems without delay.
-
Version Locking:
- Remove caret (^) and tilde (~) prefixes from
package.jsonfiles. - Pin Axios to an exact version number to prevent automatic upgrades.
- Remove caret (^) and tilde (~) prefixes from
-
Cache Cleaning:
- Run
npm cache clean --forceto flush any cached malicious packages.
- Run
-
Audit Logs:
- Review CI/CD logs for installs of affected Axios versions (0.21.1 and 0.27.2).
- Check developer machines for the presence of the
plain-crypto-jsfolder innode_modules.
-
Network Security:
- Block outbound traffic to malicious domains/IPs:
- Domain: sfrclak[.]com
- IP Address:
- Block outbound traffic to malicious domains/IPs:
Read the full article at Cyber Security News
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.

![[AINews] The Unreasonable Effectiveness of Closing the Loop](/_next/image?url=https%3A%2F%2Fmedia.nemati.ai%2Fmedia%2Fblog%2Fimages%2Farticles%2F600e22851bc7453b.webp&w=3840&q=75)



