Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT
On March 31, 2026, two malicious versions of axios, the enormously popular JavaScript HTTP client with over 100 million weekly downloads, were briefly published to npm via a compromised maintainer ...

Source: DEV Community
On March 31, 2026, two malicious versions of axios, the enormously popular JavaScript HTTP client with over 100 million weekly downloads, were briefly published to npm via a compromised maintainer account. The packages contained a hidden dependency that deployed a cross-platform remote access trojan (RAT) to any machine that ran npm install (or equivalent in other package managers like Bun) during a two-hour window. The malicious versions (1.14.1 and 0.30.4) were removed from npm by 03:29 UTC. But in the window they were live, anyone whose CI/CD pipeline, developer environment, or build system pulled a fresh install could have been compromised without ever touching a line of Axios code. TL;DR Snyk Advisory SNYK-JS-AXIOS-15850650 Affected versions [email protected], [email protected] Root cause Hijacked npm maintainer account Malicious dependency [email protected] (SNYK-JS-PLAINCRYPTOJS-15850652) Payload Cross-platform RAT (macOS, Windows, Linux) C2 server sfrclak[.]com:8000 Published 1.14.1