Looks like Drift was compromised by admin key compromise. Some speculation that maybe was tied to a dev w/ admin access locally doing a version bump on the Axios JS library, which was widely compromised yesterday 👇 Still fog of war... but would make sense

softstack ⧉
@softstackHQ
04-02
The production frontend is running Axios 1.13.6 in the vendor bundle. This version is not affected by the compromised 1.14.1 / 0.30.4 npm supply chain attack, but it is only one minor version away. An upgrade at the wrong time on a developer machine could happened...
From Twitter
Disclaimer: The content above is only the author's opinion which does not represent any position of Followin, and is not intended as, and shall not be understood or construed as, investment advice from Followin.
Like
Add to Favorites
Comments
Share
Relevant content





