This is one of the many reasons I never liked and would never like and/or trust Node and/or NPM:
https://socket.dev/blog/axios-npm-package-compromised
Welcome to the biggest supply chain attack in history.
Little context:
• Axios has about 100 million weekly downloads on npm.
• Axios is present in approximately 80% of cloud and code environments.
• Axios lists over 130,000 dependent packages.