<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Axios</title><description>Cybersecurity articles tagged #Axios on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>CVE-2026-40175: Siemens gWAP RCE via Axios Prototype Pollution</title><link>https://runtimerebel.com/blog/cve-2026-40175-siemens-gwap-rce-via-axios-prototype-pollution</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-40175-siemens-gwap-rce-via-axios-prototype-pollution</guid><description>Siemens gWAP is vulnerable to RCE via CVE-2026-40175, a prototype pollution flaw in the Axios HTTP client library. Update to v3.1.1 or later.</description><pubDate>Thu, 14 May 2026 20:40:58 GMT</pubDate><category>CVE-2026-40175</category><category>Siemens gWAP</category><category>Axios</category><category>RCE</category><category>Prototype Pollution</category><category>Critical Manufacturing</category><category>ICS</category></item><item><title>Axios npm Supply Chain Attack: Malicious Payloads and Mitigation</title><link>https://runtimerebel.com/blog/axios-npm-supply-chain-attack-malicious-payloads-and-mitigation</link><guid isPermaLink="true">https://runtimerebel.com/blog/axios-npm-supply-chain-attack-malicious-payloads-and-mitigation</guid><description>Axios npm versions 1.14.1 and 0.30.4 compromised via a malicious dependency injecting remote access trojans. Learn how to detect and remediate this threat.</description><pubDate>Tue, 21 Apr 2026 08:44:16 GMT</pubDate><category>Axios</category><category>NPM</category><category>Node Js</category><category>Plain Crypto Js</category><category>Supply Chain Compromise</category><category>CISA</category></item><item><title>OpenAI Revokes macOS App Certificate Following Supply Chain Attack</title><link>https://runtimerebel.com/blog/openai-revokes-macos-app-certificate-following-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-revokes-macos-app-certificate-following-supply-chain-attack</guid><description>OpenAI revokes its macOS app signing certificate after a GitHub Actions workflow downloaded a malicious Axios library version during a supply chain incident.</description><pubDate>Mon, 13 Apr 2026 08:48:46 GMT</pubDate><category>OpenAI</category><category>macOS</category><category>Axios</category><category>GitHub Actions</category><category>Supply Chain Security</category></item><item><title>Axios Attack: Industrialized Social Engineering on NPM Maintainers</title><link>https://runtimerebel.com/blog/axios-attack-industrialized-social-engineering-on-npm-maintainers</link><guid isPermaLink="true">https://runtimerebel.com/blog/axios-attack-industrialized-social-engineering-on-npm-maintainers</guid><description>An analysis of the Axios NPM package attack reveals advanced, scaled social engineering campaigns targeting open-source maintainers, elevating supply chain risk.</description><pubDate>Tue, 07 Apr 2026 00:41:47 GMT</pubDate><category>Axios</category><category>NPM</category><category>Social Engineering</category><category>Supply Chain Attack</category><category>Open Source Security</category><category>Maintainer Compromise</category></item><item><title>Axios npm Hijack Attempt: Detecting Social Engineering Tactics</title><link>https://runtimerebel.com/blog/axios-npm-hijack-attempt-detecting-social-engineering-tactics</link><guid isPermaLink="true">https://runtimerebel.com/blog/axios-npm-hijack-attempt-detecting-social-engineering-tactics</guid><description>North Korean threat actors targeted an Axios maintainer with a fake Microsoft Teams fix, highlighting critical risks to open-source supply chains.</description><pubDate>Sun, 05 Apr 2026 00:41:54 GMT</pubDate><category>Axios</category><category>NPM</category><category>Lazarus Group</category><category>Social Engineering</category><category>Supply Chain Security</category></item><item><title>UNC1069 Social Engineering Leads to Axios npm Supply Chain Compromise</title><link>https://runtimerebel.com/blog/unc1069-social-engineering-leads-to-axios-npm-supply-chain-compromise</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc1069-social-engineering-leads-to-axios-npm-supply-chain-compromise</guid><description>Runtime Rebel details how North Korean threat actor UNC1069 leveraged targeted social engineering against an Axios npm package maintainer, leading to a critical supply…</description><pubDate>Fri, 03 Apr 2026 16:16:04 GMT</pubDate><category>UNC1069</category><category>Axios</category><category>NPM</category><category>Supply Chain Attack</category><category>Social Engineering</category><category>North Korea</category></item><item><title>Axios NPM Supply Chain Attack Bypasses GitHub Actions CI/CD</title><link>https://runtimerebel.com/blog/axios-npm-supply-chain-attack-bypasses-github-actions-ci-cd</link><guid isPermaLink="true">https://runtimerebel.com/blog/axios-npm-supply-chain-attack-bypasses-github-actions-ci-cd</guid><description>A sophisticated supply chain attack targeted the Axios NPM package, leveraging a compromised token to bypass GitHub Actions CI/CD and deploy malicious versions.</description><pubDate>Wed, 01 Apr 2026 12:28:22 GMT</pubDate><category>Axios</category><category>NPM</category><category>Supply Chain Attack</category><category>North Korea</category><category>GitHub Actions</category><category>CI CD</category></item><item><title>Axios npm Supply Chain Attack Attributed to North Korea&apos;s UNC1069</title><link>https://runtimerebel.com/blog/axios-npm-supply-chain-attack-attributed-to-north-korea-s-unc1069</link><guid isPermaLink="true">https://runtimerebel.com/blog/axios-npm-supply-chain-attack-attributed-to-north-korea-s-unc1069</guid><description>Google Threat Intelligence attributes a major Axios npm supply chain attack to North Korean group UNC1069, emphasizing risks to developer environments.</description><pubDate>Wed, 01 Apr 2026 08:34:33 GMT</pubDate><category>UNC1069</category><category>NPM</category><category>Axios</category><category>North Korea</category><category>Supply Chain Security</category></item><item><title>UNC1069 Leverages Axios NPM Supply Chain to Deploy WAVESHAPER.V2</title><link>https://runtimerebel.com/blog/unc1069-leverages-axios-npm-supply-chain-to-deploy-waveshaper-v2</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc1069-leverages-axios-npm-supply-chain-to-deploy-waveshaper-v2</guid><description>North Korea-nexus UNC1069 compromised widely used Axios NPM package (v1.14.1, 0.30.4) by injecting plain-crypto-js to deploy WAVESHAPER.V2 backdoor across multiple OS.</description><pubDate>Wed, 01 Apr 2026 00:45:35 GMT</pubDate><category>UNC1069</category><category>WAVESHAPER V2</category><category>Axios</category><category>NPM</category><category>Supply Chain Attack</category><category>Plain Crypto Js</category><category>SILKBELL</category><category>North Korea</category></item><item><title>Axios NPM Compromise: Supply Chain Threat Analysis</title><link>https://runtimerebel.com/blog/axios-npm-compromise-supply-chain-threat-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/axios-npm-compromise-supply-chain-threat-analysis</guid><description>Analysis of the Axios NPM package compromise, a potential supply chain attack impacting JavaScript HTTP client library users, possibly by North Korean threat actors.</description><pubDate>Wed, 01 Apr 2026 00:44:25 GMT</pubDate><category>Axios</category><category>NPM</category><category>JavaScript</category><category>Supply Chain Attack</category><category>Threat Actors</category></item><item><title>Axios npm Package Hijacked: Cross-Platform Malware Distribution</title><link>https://runtimerebel.com/blog/axios-npm-package-hijacked-cross-platform-malware-distribution</link><guid isPermaLink="true">https://runtimerebel.com/blog/axios-npm-package-hijacked-cross-platform-malware-distribution</guid><description>Analysis of the Axios npm package hijack distributing remote access trojans to Linux, Windows, and macOS systems. Learn to protect your software supply chain.</description><pubDate>Tue, 31 Mar 2026 16:29:10 GMT</pubDate><category>Axios</category><category>NPM</category><category>Supply Chain Attack</category><category>Remote Access Trojan</category><category>Malware</category><category>JavaScript</category><category>Linux</category><category>Windows</category><category>macOS</category></item><item><title>Axios Supply Chain Attack: RAT Found in Versions 1.14.1 and 0.30.4</title><link>https://runtimerebel.com/blog/axios-supply-chain-attack-rat-found-in-versions-1-14-1-and-0-30-4</link><guid isPermaLink="true">https://runtimerebel.com/blog/axios-supply-chain-attack-rat-found-in-versions-1-14-1-and-0-30-4</guid><description>Malicious Axios versions 1.14.1 and 0.30.4 inject a cross-platform RAT via a fake dependency. Identify and remediate this npm supply chain threat now.</description><pubDate>Tue, 31 Mar 2026 08:29:42 GMT</pubDate><category>Axios</category><category>NPM Security</category><category>Supply Chain Attack</category><category>RAT</category><category>Javascript Security</category><category>Malicious Dependency</category></item></channel></rss>