← Back to Feed

Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly Downloads

March 31, 2026 · Trend Micro · Severity: MEDIUM

Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly Downloads. A supply chain attack hit Axios when attackers used stolen npm credentials to publish malicious versions containing a phantom dependency. This triggered a cross-platform RAT during installation and replaced its files with clean decoys, making detection challenging. Defenders should review their security posture and apply relevant mitigations as needed.

Key Takeaways

  • Analysis reveals how Axios NPM Package Compromised infects and persists on target systems.
  • Medium severity threats still pose significant risk; organizations should prioritize detection and response controls.
  • Organizations must audit third-party dependencies and implement software bill of materials (SBOM) for supply chain security.
☕ Buy a Coffee