OX Security analyzes a supply-chain compromise of axios versions 0.30.4 and 1.14.1 through the malicious [email protected] dependency. The dependency's postinstall setup.js script contacted sfrclak[.]com on port 8000, fingerprinted the operating syste…
« Reports in 2026
593 reports
OpenSourceMalware identifies TasksJacker as an active DPRK-linked supply-chain campaign that compromises GitHub repositories by adding malicious .vscode/tasks.json files configured to run when a developer opens the folder in VS Code. The campaign affected…
Invictus assessed the Axios npm compromise as a separate supply-chain incident in which a lead maintainer account was hijacked to publish trojanized versions 1.14.1 and 0.30.4. The malicious releases added plain-crypto-js, deploying a cross-platform RAT a…
Derp's analysis found that Axios 1.14.1 introduced a single new dependency, [email protected], whose postinstall hook ran an obfuscated JavaScript dropper during npm install. The compromise lasted 169 minutes, affected Axios 1.14.1 and 0.30.4, and use…
SafeDep identified malicious axios releases 1.14.1 and 0.30.4 published to npm after an apparent maintainer account compromise, with no matching GitHub tag or provenance for the 1.14.1 package. The attacker made a narrow manifest-only change by adding the…
Malicious axios versions 1.14.1 and 0.30.4 were briefly published to npm after likely compromise of a maintainer account, exposing developers and CI/CD systems that installed them during the live publication window. The attacker did not alter Axios source…
Axios npm Supply Chain Compromise (2026-03-31) — Full RE + Dynamic Analysis + BlueNoroff Attribution
The analysis attributes the March 2026 axios npm supply-chain compromise to BlueNoroff/Lazarus with high confidence, citing NukeSped classification, macWebT naming overlap with RustBucket webT, matching User-Agent behavior, Hostwinds infrastructure, and c…
Huntress observed active exploitation of the axios npm supply-chain compromise, with malicious [email protected] and [email protected] delivering a cross-platform RAT through the [email protected] postinstall hook. The update notes multiple indicators pointing …
Malicious axios versions 1.14.1 and 0.30.4 were published to npm through a compromised maintainer account, affecting both modern and legacy branches of a package with more than 100 million weekly downloads. The attacker did not alter Axios source code dir…
An attacker hijacked the npm account of Axios lead maintainer jasonsaayman and published malicious axios versions 1.14.1 and 0.30.4 on March 31, 2026. The poisoned releases added [email protected], whose postinstall script ran during npm install and d…
Datadog analyzes the March 31, 2026 axios npm compromise in which a hijacked maintainer account published [email protected] and [email protected] with a new dependency on plain-crypto-js. The typosquatted package cloned crypto-js but added a postinstall setup.js sc…
ThreatBook attributes the Axios npm supply-chain poisoning incident to Lazarus Group, citing long-term tracking, malware behavior, and infrastructure pivots. The attack used a hijacked Axios maintainer account to publish [email protected] and [email protected] with…
Socket analyzed the axios supply-chain compromise in which [email protected] and [email protected] pulled the malicious [email protected] dependency through npm. The dependency’s postinstall hook ran setup.js, decoded obfuscated module names, commands, paths, a…
The analysis describes an axios supply-chain compromise in which axios v1.14.1 and v0.30.4 were published directly through npm CLI with a malicious plain-crypto-js dependency, diverging from normal GitHub Actions OIDC provenance. The attacker reportedly c…
StepSecurity identified malicious npm releases [email protected] and [email protected] published through compromised maintainer credentials rather than the project’s normal GitHub Actions OIDC Trusted Publisher flow. The attacker added an unused runtime dependency,…