AppSec · 165 days ago
The Axios npm package, a widely used JavaScript HTTP client, was compromised via social engineering of its maintainer by North Korean threat actors UNC1069. The attackers published two malicious versions (1.14.1 and 0.30.4) that added a fabricated dependency, plain-crypto-js@4.2.1, which runs a postinstall script without user interaction. This script downloads a platform-specific remote access trojan (RAT) for macOS, Windows, or Linux from actor-controlled infrastructure and then deletes itself and restores a clean package.json to erase local forensic traces.
Detection cannot rely on local node_modules inspection because the dropper removes itself after execution. Instead, defenders must analyze npm registry publication logs and monitor network traffic for connections to the C2 server at 142.11.206.73. The attack exposes supply chains to stealthy RAT deployment through trusted package updates, requiring rollback to safe Axios versions and credential rotation for affected environments.
21 sources covering this story
Axios NPM supply chain incident
Overview of the recent Axios NPM supply chain incident including details of the payloads delivered from actor-controlled infrastructure.
UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack
UNC1069 compromised Axios 1.14.1 and 0.30.4 via social engineering, impacting 100M weekly downloads and exposing supply chains.
FortiGuard Labs Threat Signals
Threat Signal Report | FortiGuard Labs
What is the Attack?A software supply chain attack targeted the widely used JavaScript library Axios after an attacker reportedly compromised a main...
Mitigating the Axios npm supply chain compromise | Microsoft Security Blog
Although the malicious versions are no longer available for download, since Axios is one of the most widely used HTTP clients in the JavaScript ecosystem, this compromise exposed hundreds to potentially millions of users.
Threat Brief: Widespread Impact of the Axios Supply Chain Attack
Unit 42 discusses the supply chain attack targeting Axios.
Axios open-source library targeted in sophisticated supply chain attack
Researchers link the compromise to a North Korean adversary and warn the impacts could be wide ranging.
Hackers Hijack Axios npm Package to Spread RATs
Threat actors hijacked the popular npm package axios to spread RAT malware after compromising an open‑source maintainer’s account, researchers warn
Axios NPM Package Breached in North Korean Supply Chain Attack
A long-lived NPM access token was used to bypass the GitHub Actions OIDC-based CI/CD publishing workflow and push backdoored package versions.
Elastic releases detections for the Axios supply chain compromise — Elastic Security Labs
Hunting and detection rules for the Elastic-discovered Axios supply chain compromise.
Inside the Axios supply chain compromise - one RAT to rule them all — Elastic Security Labs
Elastic Security Labs analyzes a supply chain compromise of the axios npm package delivering a unified cross-platform RAT
STARDUST CHOLLIMA Likely Compromises Axios npm Package
STARDUST CHOLLIMA has likely compromised Axios Note Package Manager (npm) Package with stolen manager credentials.
Axios NPM Package Compromised in Precision Attack
The NPM package for Axios, a popular JavaScript HTTP client library, was briefly compromised this week, possibly by North Korean threat actors.
Part of the PlainSec briefing for 2026-04-04