CyberSecurityBoardThreat Intel · CVEs · Products

Tag: npm

Malware

atomic-lockfile@1.4.2: Malicious npm Package

The npm package atomic-lockfile@1.4.2 was used in the Atomic Arch campaign to deliver the deps payload via a preinstall hook. It was…

atomic-lockfile malicious package npm supply chain attack
June 25, 2026
Cyber Products

axios npm Package

axios is a popular npm package for making HTTP requests. It was compromised in March 2026 by Sapphire Sleet/UNC1069 via a post-install…

Axios HTTP npm supply chain attack
June 25, 2026