CISA Warns Axios npm Package Was Compromised in Major Supply Chain Attack
ID: 0c430efb-2427-52e9-84db-58b6e795315d
STIX ID: report--0c430efb-2427-52e9-84db-58b6e795315d
Feed Name: Cyber Press
**Executive Summary:** CISA warns that attackers compromised the Axios npm package (versions 1.14.1 and 0.30.4) on March 31, 2026 by adding a hidden dependency (plain-crypto-js v4.2.1) that acts as a loader for a remote access trojan, enabling theft of source code, environment variables, API keys, and lateral movement into enterprise CI/CD and production systems; CISA provides indicators (malicious domain Sfrclak.com, affected package names/versions) and mitigation guidance including downgrading to safe versions, removing the malicious node_modules directory, rotating credentials, enabling EDR/network monitoring, and hardening npm configurations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
