logo

Axios NPM Package Compromised in Precision Attack

ID: 9ef65a2e-f53d-58bf-a673-adb4d56ea258

STIX ID: report--9ef65a2e-f53d-58bf-a673-adb4d56ea258

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2026-03-31

Date Updated: 2026-04-22

Author: Alexander Culafi

...
...

Executive Summary: The Axios npm package was compromised with malicious releases that added a fake dependency (plain-crypto-js) which deployed a cross-platform remote access Trojan that profiles systems, fetches platform-specific payloads, and self-deletes to evade detection; the incident is described as highly sophisticated, likely aimed at access brokerage or targeted espionage, and has been attributed by some vendors to suspected North Korean actor UNC1069.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.