Navigate Select ESC Close

Millions of JS devs just got penetrated by a RAT…

2026-03-31 Science & Technology
276.8k
12.8k
865
Fireship
Fireship
4.2m subscribers

Unlock all features

FREE: Get instant access to 10 AI summaries, chats, or transcripts per day.

Description

Mux is the best video API for developers. Get $50 in free credits - https://mux.com/fireship Yesterday, a precision-guided remote access trojan was discovered in Axios, a JavaScript library with over 100 million downloads on npm. But this wasn't your average RAT - let's take a look at how this highly sophisticated attack was pulled off and what to do if you're compromised. #coding #programming #hack ℹ️ More Info: - https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan 🔖 Topics Covered - What is Axios - Axios RAT attack - What to do if you're compromised Want more Fireship? 🗞️ Newsletter: https://bytes.dev 🧠 Courses: https://fireship.dev

Top Comments (10)

@nateroskelley7565 2026-03-31

Interesting that the #1 security tip is to keep your packages up to date, and recently it feels like the best way to get hacked is to keep your packages up to date

3.8k 91 replies
@slava_trushkin 2026-03-31

Phew, I'm safe! I don't use .env, I put all data in js files directly and commit them to public repositories.

1.9k 31 replies
@srakesh95 2026-03-31

The Original title for this video was - "Millions of JS devs just got penetrated by a RAT..." LMAO

1.7k 37 replies
@amine7 2026-03-31

"If you don't keep your dependencies updated you will get hacked" they said.

975 10 replies
@steveh.7664 2026-03-31

npm install - is now considered to be one of the most dangerous commands you can use in your production environment.

674 28 replies
@RisenThe 2026-03-31

Automatic updates being a giant security risk is not talked about enough.

499 12 replies
@DataIsBeautifulOfficial 2026-03-31

My dependencies formed a criminal organization.

430 3 replies
@driftwood42 2026-03-31

You know its bad when I hear about the issue at work before I hear about it from Fireship

402 1 replies
@tearzofthefallen6586 2026-03-31

This is why my team is still on a 10 year old version of Axios and Express. We totally knew upgrading was a scam in the first place.

260 6 replies
@Michael-ty2uo 2026-03-31

I knew it was bad because I woke up to 50 messages in my cybersecurity work group chat and our IT department was freaking out

209 5 replies

Unlock the Data Inside
Turn Videos into Knowledge

  • Get FREE 10/day: transcripts, summaries, chats
  • Chat with videos, export text & PDF
  • $1 free API credit for RAG, chatbots & research

Free forever plan • All features unlocked

App screenshot