Skip to content

Instantly share code, notes, and snippets.

View andriy-sudo's full-sized avatar

Andriy Lysyuk andriy-sudo

View GitHub Profile
@andriy-sudo
andriy-sudo / axios-supply-chain-check-windows.ps1
Created April 2, 2026 09:24
axios supply chain compromise check — Windows PowerShell
#!/usr/bin/env pwsh
# axios supply chain compromise check — Windows (PowerShell 5.1+)
# Checks for compromised axios@1.14.1 / @0.30.4 and plain-crypto-js@4.2.0 / @4.2.1
# Reference: https://socket.dev/blog/axios-npm-package-compromised
$global:COMPROMISED = $false
$BACKDOOR_SUMMARY = ""
$C2_SUMMARY = ""
$PKG_SUMMARY = ""
$LOCK_SUMMARY = ""
@andriy-sudo
andriy-sudo / axios-supply-chain-check.sh
Last active March 31, 2026 17:40
axios supply chain compromise check (1.14.1 / 0.30.4) — ref ENG-13581
#!/usr/bin/env bash
# axios supply chain compromise check
# Checks for compromised axios@1.14.1 / @0.30.4 and plain-crypto-js@4.2.0 / @4.2.1
# Checks for IoC backdoor files and active C2 connections
# Reference: https://socket.dev/blog/axios-npm-package-compromised
set -euo pipefail
RED='\033[0;31m'
GREEN='\033[0;32m'