logo

Microsoft Details Steps to Mitigate the Axios npm Supply Chain Compromise

ID: 3eecdf91-74b3-53de-9967-2ba259e432ee

STIX ID: report--3eecdf91-74b3-53de-9967-2ba259e432ee

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-04-02

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A supply-chain attack compromised two Axios npm releases by adding a malicious dependency ([email protected]) which executed a post-install loader to download platform-specific RATs (Windows, macOS, Linux); Microsoft attributes the infrastructure to North Korean APT 'Sapphire Sleet' and recommends immediate rollback to 1.14.0/0.30.3, rotating exposed secrets, locking package versions, cleaning npm cache, auditing CI/CD logs, and blocking the C2 domain and IP.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.