Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Attack Feeds
  • Attack on axios software developer tool threatens widespread compromises  – CyberScoop
AttackFeed by Joe Wagner | Attack on axios software developer tool threatens widespread compromises  - CyberScoop

Attack on axios software developer tool threatens widespread compromises  – CyberScoop

Posted on March 31, 2026 By mbracken
Attack Feeds

A hacker briefly delivered malware this week through a popular open-source project for software developers that has an estimated 100 million weekly downloads, raising the possibility of compromises spreading widely through a supply-chain attack.

Axios is a JavaScript client library used in web requests. The unknown attacker hijacked the npm account — npm being a package manager for JavaScript — of the lead axios maintainer, and then published malicious versions of axios with remote access trojans to npm. That happened on Sunday night going into Monday morning, cybersecurity firm Huntress said, before the poisoned versions were pulled.

Aikido, another security firm, called it “one of the most impactful npm supply chain attacks on record.” Researchers at a large number of cyber companies have sounded alarms about the attack, including Step Security, Socket, Endor Labs and others.

According to Step Security, the malicious “[email protected]” and “[email protected]” versions inject a new software dependency, [email protected], that acts as a loader for the malware. It targets MacOS, Windows and Linux devices.

But, while the researchers describe it as malware, they note that “there are zero lines of malicious code inside axios itself.” Rather, the software is simply functioning as designed — or redesigned.

“Both poisoned releases inject a fake dependency… never imported anywhere in the axios source, whose sole purpose is to run a [post installation] script that deploys a cross-platform remote access trojan,” wrote Ashish Kurmi, chief technology officer and founder of Step Security.

Feross Aboukhadijeh, CEO and founder of Socket, called the situation “a live compromise” with a wide potential blast radius.

“This is textbook supply chain installer malware,” Aboukhadijeh wrote on X Monday evening, adding about the malicious versions that “Every npm install pulling the latest version is potentially compromised right now.”

The software package pulled in by the malicious versions of axios has embedded payloads that evade static cybersecurity analysis methods and confound human reviewers, and deletes and renames artifacts to destroy forensic evidence.

Aboukhadijeh gave blunt advice for anyone who had downloaded or used axios in the past week at least.

“If you use axios, pin your version immediately and audit your lockfiles,” he wrote. “Do not upgrade.”

Kurmi described the attack as “precision,” noting that the malicious dependency was staged less than 24 hours in advance and both malicious versions were poisoned within the same hour. 

Given the timeframe during which the malicious axios versions were online, that could translate into approximately 600,000 downloads, said Joshua Wright, SANS Institute faculty fellow and senior technical director at Counter Hack Innovations. 

“That’s a large number of compromises, and as soon as you install the software, it scrapes access credentials, and so now threat actors could pivot to AWS, other GitHub packages through scraped GitHub keys, and that’s the part that’s really difficult to articulate,” he told CyberScoop, warning that the fallout could stretch for weeks. “We’re going to see more and more stories about people that realize they’ve gotten breached, as today they’re trying to figure out what the impact is of that.”

The attack follows closely on the heels of other cases of developer-oriented targeting.

The post Attack on axios software developer tool threatens widespread compromises appeared first on CyberScoop.

  –

Read More  – CyberScoop 

Post navigation

❮ Previous Post: NCSC warns of messaging app targeting  – All Feed
Next Post: TrueConf Zero-Day Exploited in Attacks on Southeast Asian Government Networks  – The Hacker News ❯

You may also like

AttackFeed by Joe Wagner | MFA Prompt Bombing: Why Your Second Factor Isn't Saving You  - The Hacker News
Attack Feeds
MFA Prompt Bombing: Why Your Second Factor Isn’t Saving You  – The Hacker News
May 26, 2026
AttackFeed by Joe Wagner | JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware  - The Hacker News
Attack Feeds
JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware  – The Hacker News
May 28, 2026
AttackFeed by Joe Wagner | AI is Everywhere, But CISOs are Still Securing It with Yesterday's Skills and Tools, Study Finds  - The Hacker News
Attack Feeds
AI is Everywhere, But CISOs are Still Securing It with Yesterday’s Skills and Tools, Study Finds  – The Hacker News
March 17, 2026
AttackFeed by Joe Wagner | Attack on axios software developer tool threatens widespread compromises  - CyberScoop
Attack Feeds
We Are At War  – The Hacker News
March 27, 2026
  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.