logo

Supply Chain Attack Impacts Widely Used Axios npm Package

ID: a795f036-9236-539d-a84c-dd8159baf817

STIX ID: report--a795f036-9236-539d-a84c-dd8159baf817

Feed Name: Arctic Wolf Blog

Threat Score
85/100

Date Published: 2026-03-31

Date Updated: 2026-06-11

...
...

On 31 March 2026 the widely used Axios npm package was compromised: attacker-published releases ([email protected] and [email protected]) included a malicious dependency ([email protected]) whose postinstall script deployed a cross-platform remote-access trojan; the malicious packages were available for ~3 hours, exposing CI/CD pipelines, transitive consumers, and potentially credentials. Arctic Wolf advises reverting to known-safe versions, clearing caches and lockfiles, rotating exposed credentials, implementing npm mitigations (min-release-age, --ignore-scripts), and deploying detection tooling such as Arctic Wolf Agent and Sysmon.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.