A malicious Axios 1.14.1 release introduced the trojanized [email protected] dependency, making exposure broader than projects that explicitly listed Axios. The report shows how semver ranges, fresh installs, npx execution, CI tooling, developer CLIs,…
« Reports in 2026
593 reports
Hunt.io traces the Axios npm compromise to a staged operation involving takeover of maintainer jasonsaayman's npm account, publication of malicious axios releases, and weaponization of [email protected] as a postinstall dropper. The dropper hid its st…
AhnLab ASEC observed Kimsuky changing its malicious LNK distribution chain while still ultimately executing Python-based backdoors or downloaders. Recent LNK lures such as resume and data backup guide files create hidden components under C:\windirr, then …
AhnLab ASEC reported a shift in Kimsuky’s malicious LNK delivery method for Python-based backdoors and downloaders. The newer chain uses document-themed LNK lures, hidden files under C:\windirr, XML Task Scheduler entries, VBS and PowerShell scripts, Drop…
CrowdStrike reports that a threat actor used stolen maintainer credentials on March 31, 2026 to compromise the widely used Axios npm package and deploy updated, platform-specific ZshBucket variants. The activity is attributed to STARDUST CHOLLIMA with mod…
Microsoft attributed the malicious axios npm releases 1.14.1 and 0.30.4 and their command-and-control infrastructure to Sapphire Sleet, a North Korean state actor. The compromise inserted the fake dependency [email protected] so npm installation or up…
Elastic Security Labs analyzed the Axios npm supply-chain compromise in which a compromised maintainer account published backdoored [email protected] and [email protected] releases that pulled the malicious plain-crypto-js dependency. The dependency used an obfusca…
Elastic Security Labs released triage and behavior-based detections for the Axios supply-chain compromise, where malicious axios versions 1.14.1 and 0.30.4 pulled in [email protected] and executed payloads through npm postinstall activity. The deliver…
Google Threat Intelligence Group reports that malicious axios releases 1.14.1 and 0.30.4 introduced plain-crypto-js as a dependency, triggering a postinstall dropper that deployed WAVESHAPER.V2 backdoors across Windows, macOS, and Linux. GTIG attributes t…
A threat actor inserted a heavily whitespace-padded JavaScript downloader into a Tailwind CSS configuration file in a private GitHub repository, causing it to execute inside developers' Node.js environments. The multistage JADESNOW chain retrieved encrypt…
Two malicious Axios npm releases, versions 1.14.1 and 0.30.4, were published after an attacker used a compromised long-lived classic npm token for the lead maintainer account. The poisoned packages added the hidden dependency plain-crypto-js 4.2.1, whose …
Attackers compromised the npm account of Axios maintainer jasonsaayman, likely through a long-lived classic npm token, and published malicious Axios versions 1.14.1 and 0.30.4. The only Axios package change was the addition of [email protected], whose…
Wiz reports that an unknown actor compromised an axios maintainer npm account on March 31, 2026 and published malicious axios versions 1.14.1 and 0.30.4. The poisoned releases introduced plain-crypto-js, whose setup.js dropper downloaded second-stage payl…
Trend Micro reported that attackers hijacked the Axios npm maintainer account and manually published malicious Axios versions 1.14.1 and 0.30.4 using stolen credentials rather than the project’s normal OIDC Trusted Publisher workflow. The poisoned release…
Sophos CTU reported that Axios versions 1.14.1 and 0.30.4 were compromised after an apparent npm maintainer account takeover and used to deploy a cross-platform RAT. The malicious dependency executed during installation, retrieved platform-specific second…