logo

Axios NPM Packages Breached in Ongoing Supply Chain Attack

ID: c713c89f-5910-5dbb-b0a6-bc12c9070e06

STIX ID: report--c713c89f-5910-5dbb-b0a6-bc12c9070e06

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-03-31

Date Updated: 2026-04-22

Author: Divya

...
...

A supply-chain attack compromised Axios npm releases (1.14.1 and 0.30.4) by publishing a malicious dependency [email protected] and using an npm postinstall dropper (setup.js) that installs a multi-platform remote access trojan. The malware uses two-layer obfuscation, fetches platform-specific payloads (Mach-O on macOS, PowerShell/VBScript on Windows, detached Python on Linux), communicates with C2 via deceptive HTTP POSTs, and erases installation traces; the intrusion likely exploited a compromised long-lived npm publishing token with permissions exceeding maintainers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.