Malicious versions of the Axios npm package were published after a maintainer account was compromised
The Facts
- Attackers published malicious Axios releases after compromising an account with permission to publish new versions of the package on npm.
- The malicious Axios versions were 1.14.1 and 0.30.4.
- The compromised releases added or pulled in a malicious dependency called plain-crypto-js.
- Researchers said the malicious package could install a remote-access trojan or otherwise give attackers remote access to affected systems.
- The malicious code targeted major operating systems including Windows, macOS, and Linux.
- The malicious Axios releases were available on npm for only a short period, with multiple reports saying they were live for about three hours before removal.
- Axios is a widely used JavaScript HTTP client package that is downloaded tens of millions of times per week.
- Security advisories urged users of the affected Axios versions to rotate secrets or credentials and treat impacted systems as potentially compromised.
Context
Which Axios versions were affected?
The malicious releases identified across reports were axios@1.14.1 and axios@0.30.4 SecLists.org,Cointelegraph,Analytics Insight,Snyk.
What did the malicious package do?
Reports say the compromised Axios releases pulled in a rogue dependency, plain-crypto-js, that executed during installation and could install a remote-access trojan or otherwise give attackers remote access to infected machines Security Boulevard,Cointelegraph,Dark Reading,SiliconANGLE.
What are users of the affected versions being told to do?
Security researchers advised anyone who installed the affected versions to downgrade to safe releases, rotate secrets and credentials, and assume the affected machine or CI environment may have been compromised SecLists.org,Snyk,Security Boulevard.
The receipts — all 64 sources
Wire services (1)
Independent coverage (50)
Facts first. Then every angle.
The day’s biggest stories in one short brief — the facts everyone agrees on, then the competing values behind the headlines. Free in your inbox.