Two bad versions of axios were live for about three hours in March 2026, installing remote access malware on macOS, Windows and Linux. Three hours is shorter than most teams take to notice. So the question is never 'did we install it' but 'which machines downloaded it during those hours'. Here is the ordered runbook: find the window, list what downloaded, rotate in the right order, then look for what was left behind.
On 4 August 2026, a worm infected 444 npm packages and 2,212 versions in under four hours. Every bad version carried a valid signature. The attacker never stole an npm token — they took a GitHub account and let the maintainer's own release pipeline sign the malware. Here is how it worked, why signatures did not help, and the four settings that would have stopped it.