AXIOS NPM Package – Supply Chain Compromise

Release Date: 31st March 2026

Impact : HIGH / CRITICAL

TLP Rating: Clear

Communication and Digital Transformation (DCDT through CERT Vanuatu (CERTVU), provides the following advisory

This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

On 31 March 2026, a sophisticated and pre-planned supply chain attack was carried out against Axios, one of the most widely used HTTP client libraries in the JavaScript ecosystem. With over 83 million weekly downloads, Axios is a foundational dependency across frontend frameworks, backend services, and enterprise applications worldwide.

The attack was executed by compromising the npm account of the primary Axios maintainer ("jasonsaayman") and using that access to publish two malicious versions of the package (1.14.1 and 0.30.4). These versions did not contain any malicious code within Axios itself. Instead, they silently injected a fake dependency — "plain-crypto-js@4.2.1" — which served as a cross-platform Remote Access Trojan (RAT) dropper.

This is a textbook supply chain attack: trusted infrastructure was weaponised to distribute malware to unsuspecting developers and organisations that simply ran "npm install" as part of their normal development or CI/CD workflow.

 

References

  1. https://thehackernews.com/2026/03/axios-supply-chain-attack-pushes-cross.html?fbclid=IwY2xjawQ5SzlleHRuA2FlbQIxMABicmlkETFlRDFDU0JGZGZHZVlmZkZ2c3J0YwZhcHBfaWQQMjIyMDM5MTc4ODIwMDg5MgABHiu5hF5z41FsQICu0y1do-jSltuNv8kM3ce8j8sHKaOjCSXNicKLI-B5ax4l_aem_XKk-191z3fu9lGpisDhUXQ
  2. https://www.malwarebytes.com/blog/news/2026/03/axios-supply-chain-attack-chops-away-at-npm-trust
  3. https://www.malwarebytes.com/blog/news/2026/03/axios-supply-chain-attack-chops-away-at-npm-trust
  4. https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/