logo

Axios Front-End Library npm Supply Chain Poisoning Alert

ID: b2ac637e-2600-5fe5-ab6a-ebc7ccd7dccd

STIX ID: report--b2ac637e-2600-5fe5-ab6a-ebc7ccd7dccd

Feed Name: Security Boulevard

Threat Score
90/100

Date Published: 2026-04-01

Date Updated: 2026-04-22

Author: NSFOCUS

...
...

NSFOCUS CERT reports that the Axios npm package was deliberately poisoned: attackers hijacked a maintainer account, released malicious versions (1.14.1 and 0.30.4) that install a cross-platform remote-access trojan through a dependency (plain-crypto-js), and used self-deletion and disguised package files to evade detection; the advisory includes IOCs, detection commands, and remediation recommendations (downgrade to safe versions, remove malicious dependency, rotate credentials, and audit CI/CD).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.