« Reports in 2026

593 reports

2026-04-01 • Hunt.io

Hunt.io traces the Axios npm compromise to a staged operation involving takeover of maintainer jasonsaayman's npm account, publication of malicious axios releases, and weaponization of [email protected] as a postinstall dropper. The dropper hid its st…

#TA444 #Bluenoroff #NPM #Axios #T1082 #T1070.004 #T1071.001 #T1195.002 #T1059.006 #T1027 #T1057 #T1547.001 #T1059.001 #T1036.005 #T1059.002 #T1055 #T1553.002
2026-03-31 • Trend Micro

Trend Micro reported that attackers hijacked the Axios npm maintainer account and manually published malicious Axios versions 1.14.1 and 0.30.4 using stolen credentials rather than the project’s normal OIDC Trusted Publisher workflow. The poisoned release…

#NPM #Axios #T1082 #T1070.004 #T1071.001 #T1195.002 #T1059.006 #T1036 #T1027 #T1059.005 #T1059.001 #T1620
2026-03-31 • Sophos

Sophos CTU reported that Axios versions 1.14.1 and 0.30.4 were compromised after an apparent npm maintainer account takeover and used to deploy a cross-platform RAT. The malicious dependency executed during installation, retrieved platform-specific second…

#NPM #Axios