Attackers trojanize Axios HTTP library in highest-impact npm supply chain attack
Summary
Attackers compromised the npm account of Axios' lead maintainer and published malicious versions (axios@1.14.1 and axios@0.30.4) containing a remote access trojan (malware that gives attackers control over infected computers). The attack was detected within minutes and packages were removed within 2-3 hours, but the damage was significant because Axios receives roughly 100 million downloads per week and is used in 80% of cloud and code environments.
Classification
Affected Vendors
Related Issues
Original source: https://www.csoonline.com/article/4152696/attackers-trojanize-axios-http-library-in-highest-impact-npm-supply-chain-attack.html
First tracked: March 31, 2026 at 08:00 PM
Classified by LLM (prompt v3) · confidence: 75%