I audited 10 common npm packages. Three came back CRITICAL. One was just attacked last week.
The axios supply chain attack dropped April 1st. Someone pushed malicious code through the npm...

Source: DEV Community
The axios supply chain attack dropped April 1st. Someone pushed malicious code through the npm...