[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fTWsg7BtUlv0RaKut5t1-ITapnkJkV1GwcTkn-G_IGa4":3},{"article":4,"iocs":38,"watch_terms":57},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":18,"category":19,"article_tags":22},"15700e5a-d99a-453e-b080-d6b18a17c68d","Hackers Poison Axios npm Package with 100 Million Weekly Downloads","hackers-poison-axios-npm-package-with-100-million-weekly-downloads","Axios npm Package compromised in a supply chain attack, exposing developers to malware, data theft, and full system takeover risks worldwide.","On March 31, 2026, threat actors hijacked the GitHub and npm accounts of Axios maintainer Jason Saayman, publishing poisoned versions 1.14.1 and 0.30.4 within a three-hour window. The malware, hidden in a fake dependency called plain-crypto-js, deployed a multi-platform Remote Access Trojan (RAT) that established C2 communication, exfiltrated sensitive data, and enabled remote code execution on affected developer machines. With Axios used in 80% of cloud environments and 101M weekly downloads, this represents one of the most impactful npm supply chain compromises on record.","Axios npm package compromised in supply chain attack, exposing 100M weekly downloads to RAT malware.","Security MalwareHackers Poison Axios npm Package with 100 Million Weekly Downloads Axios npm Package compromised in a supply chain attack, exposing developers to malware, data theft, and full system takeover risks worldwide. byDeeba AhmedMarch 31, 20262 minute read Check your system for Axios npm Package versions 1.14.1 and 0.30.4 and remove them immediately to prevent data theft. Modern web development relies heavily on shared libraries, and few are as critical as Axios, a tool that manages how applications talk to servers. On 31 March 2026, this trust was broken when a supply chain attack ‘poisoned’ the library. With Axios used in roughly 80% of cloud environments and seeing 100 million (101,032,032) weekly downloads, this is one of the most impactful npm compromises on record. A Rapid-Fire Account Takeover The breach began when a threat actor hijacked the GitHub and npm accounts of lead maintainer Jason Saayman. According to research by Socket and OpenSourceMalware, this allowed the attacker to bypass standard security checks like OIDC signing, which usually verify code as trusted. By 00:21 UTC, the hacker published [email protected], followed by [email protected]. Both were pushed directly via a command-line interface rather than the official automated pipeline. The first infection was recorded just 89 seconds later. While collaborators like DigitalBrainJS rushed to alert the community, the attacker used stolen admin privileges to delete GitHub issues reporting the hack, playing a high-stakes cat-and-mouse game with security teams for over three hours. According to blog posts from Socket and OpenSourceMalware researchers, the actual payload was hidden inside a fake dependency called plain-crypto-js. Staged 24 hours prior, this Trojan horse was designed to look like a standard encryption library. Once a developer installed the poisoned Axios, a script inside plain-crypto-js immediately went to work. The malicious script (Source: OpenSourceMalware) A separate research from Huntress reveals the malware’s advanced stealth. As a multi-platform Remote Access Trojan (RAT), it adapted to its environment: on Windows, it renamed itself wt.exe to mimic Windows Terminal; on Macs, it hid as com.apple.act.mond to look like a native system process. Once active, the malware performed a self-destruct sequence, deleting its own files to remove any evidence of the infection. Lead maintainer’s post (Source: Huntress) Spying and Data Theft The consequences for infected machines are severe. The malware established a connection to a command-and-control server at sfrclak.com:8000, sending a heartbeat signal every 60 seconds. This beacon included a ‘fingerprint’ of the victim’s machine, including active processes and directory dumps of sensitive folders like .ssh, Documents, and OneDrive. The attackers weren’t just looking for files; they were looking for a foothold. The RAT allowed them to remotely execute commands, inject new binaries, or capture cloud API tokens. This effectively gave hackers a remote-control window into any developer’s machine that ran a standard npm install during the three-hour compromise window. What to Do If You’re Affected If you performed a build or update between 00:21 and 03:40 UTC on 31 March, your system is likely at risk. Check your lockfiles for Axios versions 1.14.1 or 0.30.4 and the plain-crypto-js package. Because the malware survives reboots and hides from basic antivirus, experts from all three firms recommend a ‘scorched earth’ approach. Do not attempt to patch the system; instead, wipe the machine completely, reinstall the OS, and immediately rotate every secret, key, and password stored on that device. Deeba Ahmed Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform’s trusted coverage. View Posts AxiosCyber AttackCybersecurityMalwareNPMSupply Chain Leave a Reply Cancel reply View Comments (0) Related Posts Security Google News Technology Google Chrome will automatically block forced website redirects Google is onto making some big changes in the way Chrome works as recently the tech and search engine giant has… byUzair Amir Read More Security Artificial Intelligence Model Namespace Reuse Flaw Hijacks AI Models on Google and Microsoft Platforms A new security vulnerability called ‘Model Namespace Reuse’ allows attackers to hijack AI models on Google, Microsoft, and… byDeeba Ahmed Security 10 Famous Bug Bounty Hunters of All Time If you are following HackRead you must be aware of what is bug bounty and how it works… byAli Raza News Security 3-month old flaw in iPhone camera app takes users to phishing sites Last week it was reported that there were a bunch of malware-infected QR reader apps on Play Store… byWaqas","https:\u002F\u002Fhackread.com\u002Fhackers-poison-axios-npm-package-100m-downloads\u002F",null,"2026-03-31T13:49:04+00:00","2026-03-31T14:00:14.712612+00:00",10,[],"26b0b636-0e31-4db1-bffb-61bdf9f20a58",{"id":18,"icon":13,"name":20,"slug":21},"Supply Chain","supply-chain",[23,28,33],{"category":24},{"id":25,"icon":13,"name":26,"slug":27},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":29},{"id":30,"icon":13,"name":31,"slug":32},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",{"category":34},{"id":35,"icon":13,"name":36,"slug":37},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[39,43,46,49,51,54],{"type":40,"value":41,"context":42},"domain","sfrclak.com","Command-and-control server contacted by RAT malware; received heartbeat signals every 60 seconds with machine fingerprint and directory dumps",{"type":27,"value":44,"context":45},"plain-crypto-js","Fake dependency trojan staged 24 hours prior; contained multi-platform RAT payload disguised as encryption library",{"type":27,"value":47,"context":48},"axios-1.14.1","Poisoned npm package version published during compromise window; contained malicious plain-crypto-js dependency",{"type":27,"value":50,"context":48},"axios-0.30.4",{"type":27,"value":52,"context":53},"wt.exe","Windows RAT masquerade name; malware renamed itself to mimic Windows Terminal process",{"type":27,"value":55,"context":56},"com.apple.act.mond","macOS RAT masquerade name; malware disguised itself as native Apple system process",[]]