I'm not giving in to the vibes yet.
Attackers stole a long-lived npm token from the lead axios maintainer and published two poisoned versions that drop a ...