Angelos Arnis 🏴 @arn.is · Mar 31

In a month there’s been at least 3 major supply chain attacks on critical packages that everyone — and most importantly vibecoders who don’t understand what they are building — are using. The latest has been on Axios (100m installs per week).

3 likes 1 replies

?

Replies

Angelos Arnis 🏴 · Mar 31

The attacker hijacked a maintainers account and published a compromised version manually bypassing the projects GitHub Actions pipeline.. A secure CI/CD becomes almost critical infra at this point. I am working on a project that tackles exactly that!