​​Supply Chain Compromise Impacts Axios Node Package Manager​

2026-04-20T19:24:19Z6793d0d4f90a8d36e63a2e35457bf5faf469ef5177d5285331690e44381e574a
CISAKEV-catalogaxioscredential-rotationdependency-tamperingincident-responseknown-exploited-vulnerabilitymalwarenpmplain-crypto-jsremote-access-trojansoftware-supply-chainsupply-chain-compromisevulnerability-management

What happened

CISA alerts that a software supply chain compromise affected the Axios npm packages: axios@1.14.1 and axios@0.30.4 were modified to include a malicious dependency plain-crypto-js@4.2.1 that downloads multi-stage payloads, including a remote access trojan. CISA recommends monitoring repos, CI/CD pipelines, developer machines, and artifact caches for installs/updates of the compromised versions; pinning dependencies; reverting to known-good states; downgrading to axios@1.14.0 or axios@0.30.3 and removing node_modules/plain-crypto-js/; and rotating or revoking exposed credentials. The bulletin is

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
6793d0d4f90a8d36e63a2e35457bf5faf469ef5177d5285331690e44381e574a
Enrichment time
2026-04-20T19:24:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ​​Supply Chain Compromise Impacts Axios Node Package Manager​ · Baitaphish