
It's been about a week since suspected hackers out of North Korea temporarily compromised axios, one of the world's most popular JavaScript HTTP client libraries. Now, more details are emerging about how the hack was achieved, and why it's pertinent knowledge for Windows, macOS, and Linux users.
The original hijacking occurred when bad actors were able to compromise axios maintainer Jason Saayman's primary account. This allowed for the publishing of two malicious axios versions to npm (a massive public registry of tools available for download) on March 30, 2026.