Major Supply Chain Compromise in the Popular axios npm Package
ID: 70c3a55d-af98-5693-9d05-3b5a0d4e574e
STIX ID: report--70c3a55d-af98-5693-9d05-3b5a0d4e574e
Feed Name: LevelBlue SpiderLabs Blog
On March 30, 2026 attackers published malicious axios releases ([email protected] and [email protected]) that introduced a dependency [email protected] which executes a postinstall dropper (setup.js) to fetch a cross-platform RAT; Google Threat Intelligence attributes the operation to UNC1069. The compromise was short-lived but high-risk given axios' widespread use; the report lists file hashes, C2 domains/IPs, and recommends scanning repos and CI logs, resetting credentials, and performing active threat hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
