Axios NPM Packages Compromised to Inject Malicious Codes in an Active Supply Chain Attack
ID: 23663132-e570-50a1-8a10-db537f12afd1
STIX ID: report--23663132-e570-50a1-8a10-db537f12afd1
Feed Name: cybersecurityNews.com
A supply-chain attack has injected a malicious transitive dependency ([email protected]) into published Axios npm releases (notably 1.14.1 and 0.30.4). The malicious package was published on 2026-03-30 and rapidly included in compromised Axios versions pushed to npm without corresponding GitHub tags, suggesting an unauthorized npm publish or account compromise; organizations using affected versions are advised to remove or roll back to safe releases (e.g., Axios 1.14.0) and conduct immediate supply-chain audits.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
