logo

Axios npm compromise traced to targeted social engineering attack

ID: bf45ed0f-71cd-5cf5-8f67-98f99ee4991b

STIX ID: report--bf45ed0f-71cd-5cf5-8f67-98f99ee4991b

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-04-03

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

The Axios npm package was compromised after a targeted social-engineering attack against its maintainer, allowing attackers to publish malicious releases that deployed a cross-platform remote access trojan; the incident highlights critical software supply-chain risk as the malicious code could spread transitively across many JavaScript projects and evade standard protections by leveraging the maintainer’s authenticated environment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.