Supply Chain Attack Impacts Widely Used Axios npm Package
ID: a795f036-9236-539d-a84c-dd8159baf817
STIX ID: report--a795f036-9236-539d-a84c-dd8159baf817
Feed Name: Arctic Wolf Blog
On 31 March 2026 the widely used Axios npm package was compromised: attacker-published releases ([email protected] and [email protected]) included a malicious dependency ([email protected]) whose postinstall script deployed a cross-platform remote-access trojan; the malicious packages were available for ~3 hours, exposing CI/CD pipelines, transitive consumers, and potentially credentials. Arctic Wolf advises reverting to known-safe versions, clearing caches and lockfiles, rotating exposed credentials, implementing npm mitigations (min-release-age, --ignore-scripts), and deploying detection tooling such as Arctic Wolf Agent and Sysmon.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
