[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fkHqVPJ9nT5z43MPqgtUn-OsumbH2qHM-mIq9JwqHi0Q":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"f30ee22c-024c-48b3-a66f-d6b2781702af","axios-library-supply-chain-compromise-delivers-cross-platform-rat","c7a92923-c483-4a5b-8c5d-6e480f41a381","Axios Library Supply Chain Compromise Delivers Cross-Platform RAT","Attackers compromised an npm account to inject malicious dependencies into the widely-used Axios JavaScript library, affecting versions v1.14.1 and v0.30.4. The malicious plain-crypto-js dependency deployed a sophisticated cross-platform Remote Access Trojan (RAT) capable of compromising Windows, macOS, and Linux systems with reconnaissance and persistence capabilities. This supply chain attack demonstrates how a single compromised developer account can weaponize trusted open-source libraries to deliver malware at scale across multiple sectors globally. The attack's attribution to DPRK-linked actors and its widespread impact highlight the critical importance of securing the software supply chain and validating third-party dependencies.","**Immediate actions:**\n- Audit all projects using Axios library versions v1.14.1 and v0.30.4 for potential compromise\n- Update to verified clean versions of Axios and remove any plain-crypto-js dependencies\n- Scan systems that may have executed affected versions for indicators of compromise\n\n**Supply chain security:**\n- Implement dependency scanning tools to detect malicious packages before deployment\n- Enable package integrity verification using checksums and digital signatures\n- Establish allow-lists of approved third-party libraries and repositories\n\n**Long-term improvements:**\n- Deploy Software Bill of Materials (SBOM) tracking for all applications and dependencies\n- Create isolated development environments with restricted internet access for dependency management\n- Implement automated security testing in CI\u002FCD pipelines to detect suspicious package behavior",[12,13,14,15,16],"CIS Control 2","NIST SP 800-161","NIST SSDF","CIS Control 16","OWASP SCVS","published","2026-04-01T19:07:47.07902+00:00","2026-04-01T19:07:46.642+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fbit.ly\u002F3O1DbOp","threat-brief-widespread-impact-of-the-axios-supply-chain-attack","Threat Brief: Widespread Impact of the Axios Supply Chain Attack",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":32,"name":33,"slug":34,"description":35,"color":36},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]