3/ What to do?
Check your lockfiles for axios 1.14.1 or 0.30.4. Run `npm ls plain-crypto-js` to see if the malicious dependency landed in your tree. If you find it, isolate affected systems immediately and rotate every secret on those machines. API keys, SSH keys, cloud creds, npm tokens - all of it. Don't try to clean compromised systems. Rebuild from a known-clean snapshot.
⬇️