Hijacked maintainer account used to publish poisoned axios releases including 1.14.1 and 0.30.4. The attacker injected a hidden dependency that drops a cross platform RAT.
Thought to do a live on YT teaching AdonisJS.
Spent 2 hours setting up the perfect screenshare, mic check, lighting, even made a sick thumbnail :)
But as I Hit 'GO LIVE'... and @YouTube decided to crash harder than a Node server with no error handling.
Entire YT Studio is down