Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly Downloads
ID: 863623e6-c8f1-527b-9e7c-9555c0925416
STIX ID: report--863623e6-c8f1-527b-9e7c-9555c0925416
Feed Name: TrendAI Security Blog
Executive summary: A high-impact software supply-chain attack compromised the Axios npm maintainer account and pushed poisoned releases ([email protected] and [email protected]) that added a phantom dependency [email protected]; its postinstall hook executed an obfuscated dropper (setup.js) that fetched platform-specific RAT payloads for macOS, Windows, and Linux, self-destructed and swapped clean manifests to hide evidence. The campaign used stolen npm tokens to bypass OIDC Trusted Publisher protections, was active in multiple industries per telemetry, and includes detailed IOCs, hashes, network indicators, MITRE TTP mappings, and mitigation guidance (pin safe versions, rotate credentials, block C2 domain, use npm ci --ignore-scripts).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
