logo

Hackers Hijack Axios npm Package to Spread RATs

ID: e9c86333-9d86-56a5-b083-8dceb5b8e52f

STIX ID: report--e9c86333-9d86-56a5-b083-8dceb5b8e52f

Feed Name: Infosecurity Magazine (News)

Threat Score
90/100

Date Published: 2026-04-01

Date Updated: 2026-04-22

...
...

Threat actors compromised the npm account of axios maintainer Jason Saayman and inserted a malicious dependency (plain-crypto-js) into axios, publishing v1.14.1 and v0.30.4 that deploy cross-platform remote access trojans; Google GTIG attributes the activity to UNC1069 (North Korea-nexus) and warns of widespread impact given axios's extensive use, while recommended mitigations include checking lockfiles, hunting for IOCs, and rotating credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.