# 100 Million Weekly Downloads. One Malicious npm Update. - slug: 100-million-weekly-downloads-one-malicious-npm-update - date: 2026-04-02 - category: Agentics The Axios npm attack was staged over 18 hours with a decoy package to establish legitimacy. The OpenClaw ecosystem was in the blast radius. ---