@lightdash/cli
GHSA-3hfp-gqgh-xc5g
npmmalware4/2/2026
Description
Axios supply chain attack - dependency in @lightdash/cli may resolve to compromised axios versions
References (9)
https://github.com/lightdash/lightdash/security/advisories/GHSA-3hfp-gqgh-xc5ggithub_advisoryhttps://github.com/axios/axios/issues/10604github_advisoryhttps://github.com/advisories/GHSA-fw8c-xr5c-95f9github_advisoryhttps://github.com/lightdash/lightdashgithub_advisoryhttps://security.snyk.io/vuln/SNYK-JS-AXIOS-15850650github_advisoryhttps://security.snyk.io/vuln/SNYK-JS-PLAINCRYPTOJS-15850652github_advisoryhttps://socket.dev/blog/axios-npm-package-compromisedgithub_advisoryhttps://thehackernews.com/2026/03/axios-supply-chain-attack-pushes-cross.htmlgithub_advisoryhttps://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojangithub_advisory
Details
Ecosystemnpm
Attack Typemalware
Published4/2/2026
Affected Versions
0.1800.0
Quick Actions