OpenSSF/OSV advisory MAL-2026-10727 confirms this npm version as malicious. `axios-test-one` impersonates the real `axios` package: manifest reuses axios's description, repository URL (`https://github.com/axios/axios.git`), and homepage (`https://axios-http.com`), with author `Jay` and a version (`1.19.4`, `Copyright (c) 2026`) ahead of upstream. README and CHANGELOG are copies of axios's. The package declares a runtime dependency on `telemetry-metrics ^0.2.2`, an author-controlled sibling...
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/browser/axios.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/axios.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/axios.min.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/esm/axios.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/esm/axios.min.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/browser/axios.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/axios.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/axios.min.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/esm/axios.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/esm/axios.min.jsView on unpkg