Axios: Malicious Versions of Published on npm
In a significant security breach, two malicious versions of the widely used JavaScript library axios were published on the npm platform on March 31, 2026. The versions, identified as v1.14.1 and v0.30.4, were live for approximately 2 hours and 53 minutes and 2 hours and 15 minutes, respectively, before being removed shortly after their discovery.
The attack was executed using the compromised credentials of a lead maintainer of axios, allowing the assailant to inject a malicious package named plain-crypto-js@4.2.1 as a dependency. This malicious package was designed to evade detection by masquerading as a legitimate component, thereby increasing its potential impact.
Prior to the publication of the malicious versions, the attack was pre-staged over an 18-hour period, indicating a high level of planning and sophistication. The malicious versions of axios were downloaded extensively, given that axios boasts over 100 million weekly downloads and is utilized in approximately 80% of cloud and code environments.
Key moments
The attack involved a cross-platform Remote Access Trojan (RAT) that targeted macOS, Windows, and Linux systems. Once installed, the RAT dropper executed a postinstall script that contacted a command-and-control server, potentially compromising the security of affected systems. Observations indicated that execution of the malicious code occurred in 3% of the environments where the malicious versions were deployed.
Security experts from StepSecurity detected the attack using their AI Package Analyst and Harden-Runner tools, which are employed in over 12,000 public repositories. The detection was facilitated by an anomalous connection that had not appeared in any prior workflow run, highlighting the effectiveness of these security measures.
In response to the incident, organizations are being strongly advised to audit their environments for any potential execution of the compromised versions of axios. Security professionals have noted that there are zero lines of malicious code within the axios library itself, emphasizing that the attack’s danger lies in the external dependencies introduced by the malicious versions.
This incident is being described as one of the most operationally sophisticated supply chain attacks ever documented against a top-10 npm package. As the software development community continues to grapple with the implications of this breach, the focus remains on enhancing security measures to prevent similar incidents in the future.
Author
bot@newscricket.org
Related Posts
RBI
The Reserve Bank of India has launched a Benchmark Issuance Strategy for market borrowings, impacting nine states and RBL Bank's foreign investment.
Zimbabwe Cricket Set for T20 Series Against India in 2026
Zimbabwe is set to host India for a three-match T20 International series in July 2026, a significant opportunity for the team and...
Read out all
Annamalai: K ‘s Absence from BJP Candidate List for Tamil Nadu Elections
K Annamalai was not included in the BJP's candidate list for the upcoming Tamil Nadu elections, raising questions about his future in...
Read out all
Kuwait Attack Today: Iranian Drones Target Refinery and Desalination Plant
Today, Iranian drones struck key infrastructure in Kuwait, including the Mina al-Ahmadi refinery and a desalination plant, causing significant damage but no...
Rohini Sindhuri Faces Corruption Allegations in Karnataka
Rohini Sindhuri, a senior IAS officer, is under scrutiny for alleged corruption related to the procurement of eco-friendly bags in Karnataka.
US Army Chief Randy George Dismissed Amid Controversy
Pete Hegseth has announced the immediate retirement of US Army Chief Randy George, citing disputes over military promotions. This marks a significant...
