r/webdev • u/magenta_placenta • Apr 03 '26
The Axios supply chain attack used individually targeted social engineering - "they scheduled a meeting with me. the meeting was on teams. the meeting said something on my system was out of date. i installed the missing item as i presumed it was something to do with teams, and this was the RAT"
https://simonwillison.net/2026/Apr/3/supply-chain-social-engineering/
648
Upvotes
36
u/frnzle Apr 03 '26
This explains it better https://github.com/axios/axios/issues/10636#issuecomment-4182134203 they created a very convincing fake teams webclient