New Research: Supply Chain Attack on Axios Pulls Malicious Dependency from npm.Details
Socket
Book a DemoSign in
Socket

URL strings

Severity

Low

Short Description

Package contains fragments of external URLs or IP addresses, which the package may be accessing at runtime.

Suggestion

Review all remote URLs to ensure they are intentional, pointing to trusted sources, and not being used for data exfiltration or loading untrusted code at runtime.