Skip to content
ReframedNewsLeft · Right · Centered
Today's StoriesArchiveAboutSign in
Today’s Stories›Business & Markets

Malicious versions of the Axios npm package were published after a maintainer account was compromised

First covered Tuesday, March 31, 2026Business & MarketsWell-covered

The Facts

  • Attackers published malicious Axios releases after compromising an account with permission to publish new versions of the package on npm.
  • The malicious Axios versions were 1.14.1 and 0.30.4.
  • The compromised releases added or pulled in a malicious dependency called plain-crypto-js.
  • Researchers said the malicious package could install a remote-access trojan or otherwise give attackers remote access to affected systems.
  • The malicious code targeted major operating systems including Windows, macOS, and Linux.
  • The malicious Axios releases were available on npm for only a short period, with multiple reports saying they were live for about three hours before removal.
  • Axios is a widely used JavaScript HTTP client package that is downloaded tens of millions of times per week.
  • Security advisories urged users of the affected Axios versions to rotate secrets or credentials and treat impacted systems as potentially compromised.

Context

Which Axios versions were affected?

The malicious releases identified across reports were axios@1.14.1 and axios@0.30.4 SecLists.org,Cointelegraph,Analytics Insight,Snyk.

What did the malicious package do?

Reports say the compromised Axios releases pulled in a rogue dependency, plain-crypto-js, that executed during installation and could install a remote-access trojan or otherwise give attackers remote access to infected machines Security Boulevard,Cointelegraph,Dark Reading,SiliconANGLE.

What are users of the affected versions being told to do?

Security researchers advised anyone who installed the affected versions to downgrade to safe releases, rotate secrets and credentials, and assume the affected machine or CI environment may have been compromised SecLists.org,Snyk,Security Boulevard.

See this differently than someone you know would?

The receipts — all 64 sources

Wire services (1)

APCointelegraphAxios NPM Package Compromised in Supply Chain Attack

Independent coverage (50)

ITProUK'The build pipeline is becoming the new frontline': Axios np...
Pravda ENNorth Korea Poisons Axios npm Packages
Infosecurity MagazineHackers Hijack Axios npm Package to Spread RATs
Cyber Security NewsNorth Korean Hackers Compromise Widely Used Axios Package to...
Security BoulevardGoogle Says North Korea Was Behind the Axios npm Supply Chai...
The Cyber ExpressNorth Korea's Lazarus Group Behind The Axios Npm Supply Chai...
Security BoulevardAxios Front-End Library npm Supply Chain Poisoning Alert
VentureBeatHackers slipped a trojan into axios, the code library behind...
RocketNews | Top News Stories From Around the GlobeHackers slipped a trojan into the code library behind most o...
El-Balad.comAxios Npm: Supply Chain Compromise Strikes Package with 100M...
simonwillison.netSupply Chain Attack on Axios Pulls Malicious Dependency from...
AllTocWhat happened in the Axios Axios supply-chain attack?
WebProNewsThe Invisible Saboteur: How Open-Source Supply Chain Attacks...
YourTownNewsAxios: What Happened with in March 2026? - YourTownNews
IT Security News - cybersecurity, infosecurity newsNorth Korea-Nexus Threat Actor Compromises Widely Used Axios...
Dark ReadingAxios NPM Package Compromised in Precision Attack
Hot for SecurityTechnical Advisory: Axios npm Supply Chain Attack - Cross-Pl...
therecord.mediaGoogle links axios supply chain attack to North Korean group
Arctic WolfSupply Chain Attack Impacts Widely Used Axios npm Package | ...
ActiveStateIt's Zero Day! Do You Know Where Your Vulnerabilities Are?
sonatype.comAxios Compromise on npm Introduces Hidden Malicious Package
IT Security News - cybersecurity, infosecurity newsSupply chain attack on Axios npm package: Scope, impact, and...
FortiGuard LabsThreat Signal Report | FortiGuard Labs
AxiosNorth Korean hackers implicated in major supply chain attack
news.bloomberglaw.comNorth Korean Hackers Suspected in Axios Software Tool Breach...
Security AffairsAttackers hijack Axios npm account to spread RAT malware
Analytics InsightAxios Supply Chain Attack Exposes Crypto Wallets to Hidden M...
Security BoulevardSupply chain attack on Axios npm package: Scope, impact, and...
PC Mag Middle EastHacker Tries to Spread Malware to Millions by Hitting 'Axios...
SecLists.orgAxios Supply-Chain Attack [v1.14.1] [0.30.4] --> plain-crypt...
CyberScoopAttack on axios software developer tool threatens widespread...
Security BoulevardAxios Hijacked: npm Account Takeover Deploys Cross-Platform ...
Insurance JournalAxios Software Tool Used by Millions Compromised in Hack
SiliconANGLEHackers compromise popular Axios Javascript library with hid...
Crypto EconomyMalicious Axios npm Release Sparks Fears of Supply‑Chain Bre...
Security BoulevardAxios supply chain attack chops away at npm trust
crypto.newsSlow Fog warns devs over malicious axios malware campaign
El-Balad.comAxios Npm supply chain attack: How poisoned releases deliver...
Claims JournalAxios Software Tool Used by Millions Compromised in Hack
CRYPTONEWSBYTES.COMAxios npm compromise puts crypto user credentials at risk
SC MediaAxios npm supply chain attack: Malicious updates add remote ...
Bloomberg BusinessAxios Software Tool Used by Millions Compromised in Hack
TechloyMalicious Axios npm Packages Installed Malware on Developer ...
The StackPopular npm package Axios poisoned
IT Security News - cybersecurity, infosecurity newsAxios npm packages backdoored in supply chain attack - IT Se...
Pravda ENAxios npm Compromise Deploys Cross-Platform RAT
TheRegister.comTop npm package backdoored to drop dirty RAT on dev machines
CyberInsiderAxios supply chain attack hits library with 400M monthly dow...
TechNaduAxios Supply Chain Attack Deploys RAT Malware
El-Balad.comAxios Npm Compromise: Malicious Releases Delivered Cross-Pla...

Facts first. Then every angle.

The day’s biggest stories in one short brief — the facts everyone agrees on, then the competing values behind the headlines. Free in your inbox.

← Earlier in this briefing
Lula says Geraldo Alckmin will again be his running mate in Brazil’s October ele...
Brazilian President Luiz Inácio Lula da Silva said Tuesday that Vice President Geraldo Alckmin will again join him on...
International Affairs
Next in this briefing →
UK competition regulator to investigate Microsoft’s business software ecosystem
The UK’s Competition and Markets Authority said it will begin a Strategic Market Status investigation into Microsoft’s...
Business & Markets

Continue Reading

More in Business & Markets

Pope Leo XIV urges Trump and world leaders to seek talks to end Iran war

Pope Leo XIV said Tuesday that he hopes President Donald Trump is looking for an "off-ramp" to end the war involving...

Business & Markets
Related this week

Missile strike on Pechenihy in Ukraine's Kharkiv region kills 10, officials say

A Russian missile strike hit the village of Pechenihy in Ukraine's northeastern Kharkiv region on the morning of 18...

International Affairs
From today's briefing

Trump says he will attend Supreme Court arguments on his birthright citizenship order

President Donald Trump said he plans to attend Wednesday's Supreme Court arguments over the legality of his executive...

U.S. Politics
Back to all stories

Facts first. Then every angle.

The day’s biggest stories in one short brief — the facts everyone agrees on, then the competing values behind the headlines. Free in your inbox.

ReframedNews

Facts first. Then left and right.

Consensus facts with cited sources, then how the left and the right each read every top story.

Navigate

Today’s StoriesArchiveSettings

Company

AboutSkylark CreationsSign InTerms of ServicePrivacy Policy

© 2026 Reframed.News

Made by Skylark Creations