What makes this attack so unsettling is that all the hackers had to do was just steal the password of one of the axios maintainers.
Analysis Shows Production-Deployable Rego Policies Would Have Prevented CMS Data Exposure, 500K-Line Source Code Leak, ...