<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[One of the worst hacks of 2026 should terrify every developer.]]></title><description><![CDATA[<p>One of the worst hacks of 2026 should terrify every developer.</p><p>The popular npm package axios was compromised after an attacker hijacked a lead maintainer account and published malicious versions. Those releases pulled in a hidden dependency that installed a cross-platform RAT on macOS, Windows and Linux.</p><p>Researchers say the malware could begin phoning home in about 1.1 seconds, then delete its own installer and replace it with clean-looking files to hide what happened.</p><p>That is the nightmare: trusted packages, automated installs, almost no visible trace.</p><p>Watch: <a href="https://www.youtube.com/watch?v=eGSsoSEppNU" rel="nofollow noopener"><span>https://www.</span><span>youtube.com/watch?v=eGSsoSEppNU</span><span></span></a></p><p>How much trust should we really place in package registries now?</p><p><a href="https://tech.lgbt/tags/NPM" rel="tag">#<span>NPM</span></a> <a href="https://tech.lgbt/tags/Axios" rel="tag">#<span>Axios</span></a> <a href="https://tech.lgbt/tags/CyberSecurity" rel="tag">#<span>CyberSecurity</span></a> <a href="https://tech.lgbt/tags/OpenSource" rel="tag">#<span>OpenSource</span></a> <a href="https://tech.lgbt/tags/InfoSec" rel="tag">#<span>InfoSec</span></a> <a href="https://tech.lgbt/tags/JavaScript" rel="tag">#<span>JavaScript</span></a> <a href="https://tech.lgbt/tags/SupplyChainSecurity" rel="tag">#<span>SupplyChainSecurity</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/b9e95b11-32d6-47e1-acb1-48134fd06757/one-of-the-worst-hacks-of-2026-should-terrify-every-developer.</link><generator>RSS for Node</generator><lastBuildDate>Mon, 06 Apr 2026 05:01:53 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/b9e95b11-32d6-47e1-acb1-48134fd06757.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 01 Apr 2026 08:53:46 GMT</pubDate><ttl>60</ttl></channel></rss>