🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise.This is textbook supply chain installer malware. axios…— Feross (@feross) March 31, 2026…