← Incident database

axios-npm-2026 · Disclosed 2026-03-31

Axios: malicious releases through publisher compromise

Google investigators reported a compromised Axios publisher account and releases carrying a malicious dependency whose install script distributes cross-platform backdoors.

Supply chain / CICredentials

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    A compromised publisher account was used to distribute malicious Axios 1.14.1 and 0.30.4.

    [s1]Overview / Remediation
  • Reported fact

    The plain-crypto-js install script retrieves payloads for Windows, macOS, and Linux.

    [s1]Initial stage

Timeline

  1. Incident disclosed. [s1]

Reported response

  • Reported fact

    Investigators recommend dependency checks, host isolation, rotation of exposed secrets, and cache remediation.

    [s1]Remediation

Evidence relevant to prevention

Operational controls to inspect

Compare lockfiles with actual build environments and install execution; pinning does not make a malicious version safe.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.

Publisher-account compromise method and total affected consumers are unknown.

Sources

  1. [s1] Google Threat Intelligence Group · Primary source

    North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package ↗

    Published 2026-03-31 · Reviewed 2026-10-02