Resources & Insights
Peter Girnus
Senior Threat Researcher
2 articles
-
BlogAxios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly Downloads
A supply chain attack hit Axios when attackers used stolen npm credentials to publish malicious versions containing a phantom dependency. This triggered a cross-platform RAT during installation and replaced its files with clean decoys, making detection challenging.
March 31st, 2026 10 minPeter Girnus, Jacob Santos
Read article -
BlogCVE-2025-55182: React2Shell Analysis, Proof-of-Concept Chaos, and In-the-Wild Exploitation
CVE-2025-55182 is a CVSS 10.0 pre-authentication RCE affecting React Server Components. Amid the flood of fake proof-of-concept exploits, scanners, exploits, and widespread misconceptions, this technical analysis intends to cut through the noise.
December 10th, 2025 21 minPeter Girnus, Deep Patel, Jack Walsh, Lucas Silva…
Read article