cybersec
Jul 24, 2026 · 6 min Supply Chain CompromiseCVE-2026-34841: The Caret That Let a RAT In
A hijacked npm maintainer account published booby-trapped `axios` tarballs, and every project whose lockfile said `^` politely fetched them. Bruno was one of them — and the fix wasn't a patch to a function, it was a lesson about how much trust a single caret encodes.
— A caret is a signed blank check