Troy's avatar
Troy 2 months ago
But isn't it just the axios library that's compromised? Or does this mean all of npm is poisoned?

Replies (3)

Troy's avatar
Troy 2 months ago
Time for everybody to fork I guess. 🤷🏻‍♂️
Axios may be included in other dependencies, or their dependencies, and so on. It’s hard to say where it might be included in a long chain. You don’t have to be directly dependent on it, because some packages in the chain might