axios-npm-2026 · Disclosed 2026-03-31
Axios: malicious releases through publisher compromise
Google investigators reported a compromised Axios publisher account and releases carrying a malicious dependency whose install script distributes cross-platform backdoors.
Outcome: Confirmed breach
Entry path and evidence
Timeline
Incident disclosed. [s1]
Reported response
- Reported fact
Investigators recommend dependency checks, host isolation, rotation of exposed secrets, and cache remediation.
[s1]Remediation
Evidence relevant to prevention
Operational controls to inspect
Compare lockfiles with actual build environments and install execution; pinning does not make a malicious version safe.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.
Publisher-account compromise method and total affected consumers are unknown.
Sources
[s1] Google Threat Intelligence Group · Primary source
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package ↗Published 2026-03-31 · Reviewed 2026-10-02