Supply chain attack on axios hit one of npm's most used libraries

On 31 March 2026, StepSecurity and Socket identified a sophisticated supply chain attack against axios, one of the most widely used HTTP client libraries in the JavaScript ecosystem, with over 100 million weekly npm downloads. Two malicious versions, 1.14.1 and 0.30.4, were published using the compromised credentials of the project's lead maintainer. The attacker changed the account's registered email address, bypassed the project's hardened CI/CD pipeline entirely by publishing manually via the npm CLI, and injected a hidden dependency, plain-crypto-js 4.2.1, whose sole purpose is to drop a cross-platform remote access trojan targeting macOS, Windows and Linux. The attack was pre-staged 18 hours in advance with a clean decoy package, and both release branches were hit within 39 minutes. Both malicious versions have since been unpublished.

What this means for your organisation

This is not only a developer problem. A compromised build machine gives the attacker whatever that machine holds, and that is often keys, certificates and access to production. Any organisation that installed axios 1.14.1 or 0.30.4 must assume compromise and act accordingly. The breadth of use also means many will be affected through a supplier without knowing it.

Berigo recommends

  • Search build logs and lockfiles for axios 1.14.1 and 0.30.4, and treat any hit as compromise.
  • Rotate keys, tokens and certificates that were reachable from affected build environments.
  • Ask the software vendors you rely on to confirm whether they were exposed.
  • Pin dependencies to specific versions and require approval before new packages enter the build pipeline.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch