logo

Major Supply Chain Compromise in the Popular axios npm Package

ID: 70c3a55d-af98-5693-9d05-3b5a0d4e574e

STIX ID: report--70c3a55d-af98-5693-9d05-3b5a0d4e574e

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
90/100

Date Published: 2026-04-03

Date Updated: 2026-04-28

Author: Karl Sigler

...
...

On March 30, 2026 attackers published malicious axios releases ([email protected] and [email protected]) that introduced a dependency [email protected] which executes a postinstall dropper (setup.js) to fetch a cross-platform RAT; Google Threat Intelligence attributes the operation to UNC1069. The compromise was short-lived but high-risk given axios' widespread use; the report lists file hashes, C2 domains/IPs, and recommends scanning repos and CI logs, resetting credentials, and performing active threat hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.