logo

Axios npm Hijack 2026: Everything You Need to Know – IOCs, Impact & Remediation

ID: 0a7bd09e-8677-5fb3-9504-e43bb26890f1

STIX ID: report--0a7bd09e-8677-5fb3-9504-e43bb26890f1

Feed Name: SOCRadar Blog

Threat Score
90/100

Date Published: 2026-03-31

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

On March 31, 2026 an attacker, using a compromised long-lived npm token and account takeover of the Axios maintainer, published two malicious Axios versions that added a hidden dependency (plain-crypto-js) which ran a postinstall dropper to install a cross-platform RAT; the packages were available for approximately 2–3 hours, produced numerous IOCs (package hashes, C2 domain/IP, filesystem paths), and the report provides detection steps, immediate remediation, and short- to medium-term supply-chain defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.