Foresight News reports that Slow Fog founder Yu Xian stated, "We are basically certain that if your OpenClaw is the latest version 3.28, it may introduce a poisoned axios, everyone should be careful to check! Additionally, it's not just the OpenClaw that may introduce this directly, but related Skills may also rely on axios, leading to indirect poisoning. Of course, since axios is used widely, it's reasonable to check everywhere. Although the poisoning incident was discovered quite promptly."

Foresight News previously reported that Socket AI founder Feross issued a warning, stating that the core dependency package axios in the npm ecosystem is under active supply chain attack, with its latest version axios@1.14.1 being injected with a previously non-existent malicious package plain-crypto-js@4.2.1.