logo

CISA Warns Axios npm Package Was Compromised in Major Supply Chain Attack

ID: 0c430efb-2427-52e9-84db-58b6e795315d

STIX ID: report--0c430efb-2427-52e9-84db-58b6e795315d

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-04-21

Date Updated: 2026-04-21

Author: AnuPriya

...
...

**Executive Summary:** CISA warns that attackers compromised the Axios npm package (versions 1.14.1 and 0.30.4) on March 31, 2026 by adding a hidden dependency (plain-crypto-js v4.2.1) that acts as a loader for a remote access trojan, enabling theft of source code, environment variables, API keys, and lateral movement into enterprise CI/CD and production systems; CISA provides indicators (malicious domain Sfrclak.com, affected package names/versions) and mitigation guidance including downgrading to safe versions, removing the malicious node_modules directory, rotating credentials, enabling EDR/network monitoring, and hardening npm configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.