Elektrine lite

← Feed

@acdha@code4lib.social

Post #944843

2026-03-31 12:14 UTC

The NPM Axios package maintainer suffered an account takeover: https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan Even if you’re unaffected now, it’s a great time to set a dependency cooldown period for everything you use. If you use #NodeJS, enable minimum package age in NPM/PNPM/Bun/Yarn. If you use #Python, enable exclude-newer in uv, minimum age in pip, or help the Poetry maintainers finish the open PR: https://github.com/python-poetry/poetry/pull/10763

Replies (0)

No replies.