Voices
Vercel Publishes Axios Compromise Remediation Steps for Affected Deployments
Vercel published an official changelog entry with specific remediation steps for projects affected by the axios supply chain attack, advising teams to downgrade to [redacted] or 0.30.3, remove node_modules/plain-crypto-js, and reinstall with --ignore-scripts. The fact that Vercel — one of the largest deployment platforms — issued a dedicated remediation guide underscores the blast radius; any CI/CD pipeline that ran npm install during the two-hour window potentially deployed the RAT to production infrastructure.
↳ Follow the thread