← Back to Feed

Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly Downloads

March 31, 2026 · Trend Micro · Severity: MEDIUM

A supply chain attack hit Axios when attackers used stolen npm credentials to publish malicious versions containing a phantom dependency. This triggered a cross-platform RAT during installation and replaced its files with clean decoys, making detection challenging.

Key Takeaways

  • A supply chain attack hit Axios when attackers used stolen npm credentials to publish malicious versions containing a phantom dependency.
  • The malicious package triggered a cross-platform RAT during installation and replaced its files with clean decoys, making detection challenging.
  • Organizations using Axios should verify installed versions and audit dependencies, given the package's over 100 million weekly downloads.
☕ Buy a Coffee