Security alert: Axios npm supply chain attack
ID: 38ccf5c9-75c7-5871-9b27-0a4733635bb0
STIX ID: report--38ccf5c9-75c7-5871-9b27-0a4733635bb0
Feed Name: Expel Blog
**Executive Summary:** The Axios npm package was briefly compromised on March 30–31, 2026 when attackers added a malicious dependency ([email protected]) that caused installs/updates to download and run a cross-platform remote access trojan (Windows/macOS/Linux) from attacker infrastructure (e.g., http://sfrclak.com:8000/6202033), potentially exposing npm tokens, AWS keys, SSH keys and other credentials; Expel SOC detected the activity and is coordinating remediation and threat hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
