{"id":695678,"date":"2026-03-31T21:14:16","date_gmt":"2026-03-31T21:14:16","guid":{"rendered":"https:\/\/www.europesays.com\/us\/695678\/"},"modified":"2026-03-31T21:14:16","modified_gmt":"2026-03-31T21:14:16","slug":"attack-on-axios-software-developer-tool-threatens-widespread-compromises","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/us\/695678\/","title":{"rendered":"Attack on axios software developer tool threatens widespread compromises"},"content":{"rendered":"<p>A hacker briefly delivered malware this week through a popular open-source project for software developers that has an estimated 100 million weekly downloads, raising the possibility of compromises spreading widely through a supply-chain attack.<\/p>\n<p>Axios is a JavaScript client library used in web requests. The unknown attacker hijacked the npm account \u2014 npm being a package manager for JavaScript \u2014 of the lead axios maintainer, and then published malicious versions of axios with remote access trojans to npm. That happened on Sunday night going into Monday morning, cybersecurity firm <a href=\"https:\/\/www.huntress.com\/blog\/supply-chain-compromise-axios-npm-package\" rel=\"nofollow noopener\" target=\"_blank\">Huntress<\/a> said, before the poisoned versions were pulled.<\/p>\n<p><a href=\"https:\/\/www.aikido.dev\/blog\/axios-npm-compromised-maintainer-hijacked-rat\" rel=\"nofollow noopener\" target=\"_blank\">Aikido<\/a>, another security firm, called it \u201cone of the most impactful npm supply chain attacks on record.\u201d Researchers at a large number of cyber companies have sounded alarms about the attack, including <a href=\"https:\/\/www.stepsecurity.io\/blog\/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan\" rel=\"nofollow noopener\" target=\"_blank\">Step Security<\/a>, <a href=\"https:\/\/socket.dev\/blog\/axios-npm-package-compromised\" rel=\"nofollow noopener\" target=\"_blank\">Socket<\/a>,<a href=\"https:\/\/www.endorlabs.com\/learn\/npm-axios-compromise\" rel=\"nofollow noopener\" target=\"_blank\"> Endor Labs<\/a> and others.<\/p>\n<p>According to Step Security, the malicious \u201caxios@1.14.1\u201d and \u201caxios@0.30.4\u201d versions inject a new software dependency, plain-crypto-js@4.2.1, that acts as a loader for the malware. It targets MacOS, Windows and Linux devices.<\/p>\n<p>But, while the researchers describe it as malware, they note that \u201cthere are zero lines of malicious code inside axios itself.\u201d Rather, the software is simply functioning as designed \u2014 or redesigned.<\/p>\n<p>\u201cBoth poisoned releases inject a fake dependency\u2026 never imported anywhere in the axios source, whose sole purpose is to run a [post installation] script that deploys a cross-platform remote access trojan,\u201d wrote Ashish Kurmi, chief technology officer and founder of Step Security.<\/p>\n<p>Feross Aboukhadijeh, CEO and founder of Socket, called the situation \u201ca live compromise\u201d with a wide potential blast radius.<\/p>\n<p>\u201cThis is textbook supply chain installer malware,\u201d Aboukhadijeh <a href=\"https:\/\/x.com\/feross\/status\/2038807290422370479\" rel=\"nofollow\">wrote on X Monday evening<\/a>, adding about the malicious versions that \u201cEvery npm install pulling the latest version is potentially compromised right now.\u201d<\/p>\n<p>The software package pulled in by the malicious versions of axios has embedded payloads that evade static cybersecurity analysis methods and confound human reviewers, and deletes and renames artifacts to destroy forensic evidence.<\/p>\n<p>Aboukhadijeh gave blunt advice for anyone who had downloaded or used axios in the past week at least.<\/p>\n<p>\u201cIf you use axios, pin your version immediately and audit your lockfiles,\u201d he wrote. \u201cDo not upgrade.\u201d<\/p>\n<p>Kurmi described the attack as \u201cprecision,\u201d noting that the malicious dependency was staged less than 24 hours in advance and both malicious versions were poisoned within the same hour.\u00a0<\/p>\n<p>Given the timeframe during which the malicious axios versions were online, that could translate into approximately 600,000 downloads, said Joshua Wright, SANS Institute faculty fellow and senior technical director at Counter Hack Innovations.\u00a0<\/p>\n<p>\u201cThat\u2019s a large number of compromises, and as soon as you install the software, it scrapes access credentials, and so now threat actors could pivot to AWS, other GitHub packages through scraped GitHub keys, and that\u2019s the part that\u2019s really difficult to articulate,\u201d he told CyberScoop, warning that the fallout could stretch for weeks. \u201cWe\u2019re going to see more and more stories about people that realize they\u2019ve gotten breached, as today they\u2019re trying to figure out what the impact is of that.\u201d<\/p>\n<p>The attack follows closely on the heels of other cases of <a href=\"https:\/\/www.theregister.com\/2026\/03\/30\/telnyx_pypi_supply_chain_attack_litellm\/\" rel=\"nofollow noopener\" target=\"_blank\">developer-oriented targeting<\/a>.<\/p>\n<p>Google Threat Intelligence Group said the attack wasn\u2019t related to the recent TeamPCP attacks, however, instead saying it had attributed the axios attack to a suspected North Korean hacking group it labels UNC1069.<\/p>\n<p>\u201cKorean hackers have deep experience with supply chain attacks, which they\u2019ve historically used to steal cryptocurrency,\u201d said John Hultquist, the unit\u2019s chief analyst. \u201cThe full breadth of this incident is still unclear, but given the popularity of the compromised package, we expect it will have far reaching impacts.\u201d<\/p>\n<p>This story was updated March 31, 2026, with comments from Google Threat Intelligence Group.<\/p>\n<p>\n\t\t\tWritten by Tim Starks and Derek B. Johnson\n\t\t<\/p>\n","protected":false},"excerpt":{"rendered":"A hacker briefly delivered malware this week through a popular open-source project for software developers that has an&hellip;\n","protected":false},"author":3,"featured_media":695679,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[6],"tags":[64,291140,51658,291141,67,132,68],"class_list":["post-695678","post","type-post","status-publish","format-standard","has-post-thumbnail","category-business","tag-business","tag-javascript","tag-malware","tag-supply-chain-attacks","tag-united-states","tag-unitedstates","tag-us"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@us\/116325860346480777","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts\/695678","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/comments?post=695678"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts\/695678\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/media\/695679"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/media?parent=695678"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/categories?post=695678"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/tags?post=695678"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}