Axios compromised on NPM – Malicious versions drop remote access trojan
8.7 relevance
Score Breakdown
technical depth 9
novelty 7
actionability 9
community 10
strategic 9
personal 9
Scored daily by a customisable AI persona to surface the most relevant engineering leadership news.
Axios NPM compromise, critical supply chain attack affecting developer dependencies.
Summary
Poisoned releases of axios@1.14.1 and 0.30.4 injected a fake dependency, plain-crypto-js@4.2.1, whose postinstall script acts as a cross-platform RAT dropper contacting sfrclak.com:8000. The attack, staged 18 hours in advance with self-destructing payloads, was detected by StepSecurity Harden-Runner via anomalous outbound connections during CI runs in projects like Backstage.