T1195.002

Compromise Software Supply Chain

discovered 2026-05-26

Typosquat of axios published to npm as turbo-axios and faster-axios, copying legitimate axios source and metadata to appear trustworthy while smuggling a postinstall payload.

View on MITRE ATT&CK

Seen in packages

Campaigns