← Back to Feed
Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly Downloads
March 31, 2026 · Trend Micro · Severity: MEDIUM
A supply chain attack hit Axios when attackers used stolen npm credentials to publish malicious versions containing a phantom dependency. This triggered a cross-platform RAT during installation and replaced its files with clean decoys, making detection challenging.
Key Takeaways
- A supply chain attack hit Axios when attackers used stolen npm credentials to publish malicious versions.
- The malicious versions contained a phantom dependency that triggered a cross-platform RAT during installation.
- Malware files were replaced with clean decoys, making detection challenging.