logo

Attack on axios software developer tool threatens widespread compromises

ID: 5cbdc125-ce85-59ad-8aa9-7c91db413667

STIX ID: report--5cbdc125-ce85-59ad-8aa9-7c91db413667

Feed Name: DataBreaches.Net

Threat Score
88/100

Date Published: 2026-03-31

Date Updated: 2026-04-19

Author: Dissent

...
...

On March 31, 2026, an attacker hijacked the npm account of Axios’s lead maintainer and published two malicious Axios package releases that contained a hidden dependency installing a cross-platform remote access trojan; the poisoned releases were available for about 2–3 hours before npm removed them, raising major supply-chain compromise concerns for a library with ~100 million weekly downloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.