Axios got compromised. They attacked the human, not code.
Infected Axios hit npm for 3 hours after attackers social-engineered the lead maintainer with a fake company, fake Slack, and a fake Teams meeting.

Source: DEV Community
Infected Axios hit npm for 3 hours after attackers social-engineered the lead maintainer with a fake company, fake Slack, and a fake Teams meeting.