Axios NPM Package Compromised in Precision Attack

2026-04-01T02:51:41Z0789670bafc810c2805bebc60ac6bfb4b69841d647d8725ad656dbe347d38cee
CVE-2025-53521ai-malwareaxioscheckmarxcloud-credentialscode-injectiondeeploadf5-big-ipkicslangflownation-state-activity','north-korea','iran','china','post-quantmno-click-vulnnpmopen-source-supply-chainopenclawover-privilegercestolen-credentialssupply-chainteamPCPtelegramtrivytrojanvertex-aivs-code-extension

What happened

This DarkReading roundup highlights a surge of high-risk supply-chain and AI-related threats: the Axios NPM package was briefly compromised (likely nation-state linked), Trivy and other developer tools were abused to deliver info-stealers into CI/CD, and multiple code-reuse/plug-in ecosystems (Checkmarx KICS, VS Code extensions, LiteLLM) were targeted. Critical vulnerabilities and exploitation activity were reported — notably F5 BIG-IP reclassified as an RCE (CVE-2025-53521) and a Langflow code-injection flaw rapidly under attack — alongside a high-severity alleged no-click Telegram flaw and a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
0789670bafc810c2805bebc60ac6bfb4b69841d647d8725ad656dbe347d38cee
Enrichment time
2026-04-01T02:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.