Supply Chain Compromise Impacts Axios Node Package Manager
2026-04-20T19:24:19Z•6793d0d4f90a8d36e63a2e35457bf5faf469ef5177d5285331690e44381e574a
CISAKEV-catalogaxioscredential-rotationdependency-tamperingincident-responseknown-exploited-vulnerabilitymalwarenpmplain-crypto-jsremote-access-trojansoftware-supply-chainsupply-chain-compromisevulnerability-management
What happened
CISA alerts that a software supply chain compromise affected the Axios npm packages: axios@1.14.1 and axios@0.30.4 were modified to include a malicious dependency plain-crypto-js@4.2.1 that downloads multi-stage payloads, including a remote access trojan. CISA recommends monitoring repos, CI/CD pipelines, developer machines, and artifact caches for installs/updates of the compromised versions; pinning dependencies; reverting to known-good states; downgrading to axios@1.14.0 or axios@0.30.3 and removing node_modules/plain-crypto-js/; and rotating or revoking exposed credentials. The bulletin is
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- 6793d0d4f90a8d36e63a2e35457bf5faf469ef5177d5285331690e44381e574a
- Enrichment time
- 2026-04-20T19:24:19Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.