Supply-Chain Compromise of axios npm Package
Essential information
- Published
- 31/03/2026 16:35
- Modified
- 31/03/2026 18:49
- Tags
- 2026-03-31 axios credential-theft cross-platform npm remote access trojan supply-chain
- Related entities
- 4 observables, 15 techniques (mitre), 1 others
Description
A coordinated supply chain attack targeted the axios npm package, compromising two versions (1.14.1 and 0.30.4) by injecting a malicious dependency. The attack delivered a cross-platform Remote Access Trojan to macOS, Windows, and Linux systems. The compromise occurred through the lead maintainer's npm account, bypassing normal publishing workflows. The malicious payload performed system reconnaissance, established persistence on Windows, and provided remote access capabilities. The attack affected numerous organizations and potentially exposed sensitive credentials. Immediate mitigation steps include pinning to safe versions, removing malicious dependencies, rotating credentials, and blocking the command and control server.