Most likely, a maintainer's GitHub and npm accounts are compromised as these issues are getting deleted. I have also reported this as a vulnerability, so that a CVE can be generated.
Developers using the axios package from npm may have downloaded a malicous version that drops a Remote Access Trojan ...
A critical supply chain attack has compromised the popular JavaScript library axios, leading to developers unknowingly ...