STARDUST CHOLLIMA Likely Compromises Axios npm Package

2026-04-04T19:23:37Za6f682bb02cdc9f8b034be58cb71f75016b52227339d2659057ef8b2853f204c
CVE-2026-20929STARDUST_CHOLLIMAaxiosdependency-compromisedns-cname-abusekerberosmalicious-packagemitigationnpmpackage-integritysoftware-supply-chainsupply-chainthreat-actor

What happened

CrowdStrike published that a threat actor tracked as “STARDUST CHOLLIMA” likely compromised the popular Axios npm package, indicating a malicious supply‑chain injection that could impact any software depending on Axios (malicious code execution, credential theft, persistence). The feed also includes a separate CrowdStrike post on CVE-2026-20929 (Kerberos authentication relay via DNS CNAME abuse). Recommended immediate actions: identify and isolate systems using affected Axios versions, pin or roll back to verified clean versions, verify package checksums/signatures, block the compromised npm/​

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
crowdstrike_blog
Record identifier
a6f682bb02cdc9f8b034be58cb71f75016b52227339d2659057ef8b2853f204c
Enrichment time
2026-04-04T19:23:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.