Axios npm Hijack 2026: Everything You Need to Know – IOCs, Impact & Remediation
ID: 0a7bd09e-8677-5fb3-9504-e43bb26890f1
STIX ID: report--0a7bd09e-8677-5fb3-9504-e43bb26890f1
Feed Name: SOCRadar Blog
On March 31, 2026 an attacker, using a compromised long-lived npm token and account takeover of the Axios maintainer, published two malicious Axios versions that added a hidden dependency (plain-crypto-js) which ran a postinstall dropper to install a cross-platform RAT; the packages were available for approximately 2–3 hours, produced numerous IOCs (package hashes, C2 domain/IP, filesystem paths), and the report provides detection steps, immediate remediation, and short- to medium-term supply-chain defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
