logo

Axios: How AppSec teams should respond

ID: a60454c1-c8b9-546b-b1d7-a687cfbdd951

STIX ID: report--a60454c1-c8b9-546b-b1d7-a687cfbdd951

Feed Name: ReversingLabs Blog

Threat Score
90/100

Date Published: 2026-04-02

Date Updated: 2026-04-30

Author: Paul Roberts

...
...

The report describes a major supply-chain compromise of the widely used axios library where malicious versions added [email protected], which executed post-install scripts to deploy a cross-platform RAT that harvested credentials and secrets; the compromise spread into Python and .NET ecosystems, is attributed to North Korea-linked actors, and the document provides an incident response checklist and recommendations (dependency pinning, short-lived CI/CD credentials, xBOM adoption) to detect, remediate, and reduce downstream risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.