logo

Axios Supply Chain Attack Exposes Developers to Hidden Malware

ID: b916a56e-5c14-5307-8ddd-d5bd09c22814

STIX ID: report--b916a56e-5c14-5307-8ddd-d5bd09c22814

Feed Name: The Cyber Express

Threat Score
88/100

Date Published: 2026-03-31

Date Updated: 2026-05-08

Author: Ashish Khaitan

...
...

A compromised Axios maintainer npm account was used to publish poisoned releases ([email protected] and 0.30.4) that injected a fake dependency ([email protected]). The dependency executed a post-install script that fetched a cross-platform RAT from a C2 server, delivered macOS/Windows/Linux payloads, and performed cleanup and anti-forensics to hide the compromise; malicious packages were available for several hours before removal, potentially impacting millions of projects.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.