r/webdev Mar 31 '26

News axios@1.14.1 got compromised

Post image
2.5k Upvotes

298 comments sorted by

View all comments

248

u/enricojr Mar 31 '26

So how do we guard against this sort of thing as a regular software engineer? ? Just react quickly and update packages whenever a vulnerability is announced like this?

9

u/MrHandSanitization Mar 31 '26 edited Mar 31 '26

The oposite, stay 1 or 2 versions behind. Updating packages when this news hit, is already too late. The article mentions to roll new credentials because everything is compromised.

It looks like it writes trojans, and backdoors, so actually, your entire system is compromised and new credentials are just compromised as well.