Tip: axios Is a Vibe Coding Wake-Up Call — Check Lockfiles, Pin Exact Versions, Audit for plain-crypto-js IOCs Right Now
r/ClaudeAI / safedep.io·high signal
The axios attack specifically targets the vibe coding workflow: running npm install without reviewing dependencies. The malicious plain-crypto-js package was live for 2-3 hours, and axios is present in ~80% of cloud/code environments. Builders should immediately: (1) check lockfiles for [redacted] or @0.30.4, (2) search node_modules for plain-crypto-js, (3) pin exact dependency versions in package.json, (4) add Socket or Snyk to CI pipelines. If compromised, the RAT achieves persistence — a clean install isn't enough.