logo

axios compromised on npm: maintainer account hijacked, RAT deployed

ID: cd641d7a-b0f5-59f8-812c-2ec0d2c3246b

STIX ID: report--cd641d7a-b0f5-59f8-812c-2ec0d2c3246b

Feed Name: Aikido Security's Blog

Threat Score
90/100

Date Published: 2026-03-30

Date Updated: 2026-07-24

...
...

A malicious actor compromised the npm account of axios's primary maintainer and published two malicious releases ([email protected] and [email protected]) that add a dependency ([email protected]) whose postinstall hook deploys a cross-platform remote access trojan for macOS, Windows, and Linux; the attack impacted a widely used library with ~100M weekly downloads, the dropper self-deletes to evade inspection, and the report provides IOCs (shasums, C2 domain, file paths), detection commands, and remediation steps including pinning safe versions, removing the dropper, rotating credentials, and auditing CI/CD logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.