logo

Critical Supply Chain Attack on Axios npm Package Delivers Malware

ID: d77ccbe0-b114-5e99-8dbf-37f7cfb75501

STIX ID: report--d77ccbe0-b114-5e99-8dbf-37f7cfb75501

Feed Name: ThreatCluster

Threat Score
88/100

Date Published: 2026-03-31

Date Updated: 2026-04-03

...
...

**Critical supply-chain compromise of axios (31 March 2026):** Attackers hijacked the lead maintainer's npm account and published two malicious axios releases that included a dependency executing a post-install cross-platform remote access trojan (macOS, Windows, Linux); the malicious packages were pre-staged 18 hours earlier, available for ~3 hours, and were downloaded by many developers and CI/CD pipelines, prompting urgent advice to audit dependencies and treat affected systems as compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.