• 6 min read
• API Stronghold Team
NPM Supply Chain Attack: Why Expiring Tokens Beat Rotation
Axios fell to a persistent maintainer token that leaked and enabled credential theft. When attackers move in minutes and rotation takes days, expiration is the only math that works.
supply-chain api-keys npm credentials