STARDUST CHOLLIMA Likely Compromises Axios npm Package
2026-04-04T19:23:37Z•a6f682bb02cdc9f8b034be58cb71f75016b52227339d2659057ef8b2853f204c
CVE-2026-20929STARDUST_CHOLLIMAaxiosdependency-compromisedns-cname-abusekerberosmalicious-packagemitigationnpmpackage-integritysoftware-supply-chainsupply-chainthreat-actor
What happened
CrowdStrike published that a threat actor tracked as “STARDUST CHOLLIMA” likely compromised the popular Axios npm package, indicating a malicious supply‑chain injection that could impact any software depending on Axios (malicious code execution, credential theft, persistence). The feed also includes a separate CrowdStrike post on CVE-2026-20929 (Kerberos authentication relay via DNS CNAME abuse). Recommended immediate actions: identify and isolate systems using affected Axios versions, pin or roll back to verified clean versions, verify package checksums/signatures, block the compromised npm/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- crowdstrike_blog
- Record identifier
- a6f682bb02cdc9f8b034be58cb71f75016b52227339d2659057ef8b2853f204c
- Enrichment time
- 2026-04-04T19:23:37Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.