logo

Axios NPM Packages Compromised to Inject Malicious Codes in an Active Supply Chain Attack

ID: 23663132-e570-50a1-8a10-db537f12afd1

STIX ID: report--23663132-e570-50a1-8a10-db537f12afd1

Feed Name: cybersecurityNews.com

Threat Score
92/100

Date Published: 2026-03-31

Date Updated: 2026-05-05

Author: Guru Baran

...
...

A supply-chain attack has injected a malicious transitive dependency ([email protected]) into published Axios npm releases (notably 1.14.1 and 0.30.4). The malicious package was published on 2026-03-30 and rapidly included in compromised Axios versions pushed to npm without corresponding GitHub tags, suggesting an unauthorized npm publish or account compromise; organizations using affected versions are advised to remove or roll back to safe releases (e.g., Axios 1.14.0) and conduct immediate supply-chain audits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.