Mitigating the Axios npm supply chain compromise

2026-04-02T02:52:23Z3f4fe0301dd174cd00c633d48d9e333c66f5b604e93547e6698b93c1a6d62591
AI‑securityCI/CDGPOMSINorth KoreaOWASPSapphire SleetVBScriptagentic‑AIaxiosbackdoorcredential‑stealercritical‑infrastructuredefenderhigh‑value‑assetsidentity‑securityincident‑responsemalwaremitigationnpmransomwaresupply-chaintrivywhatsapp

What happened

Microsoft Security Blog (late March–early April 2026) highlights multiple high‑impact threats and mitigations: a March 31 Axios npm supply‑chain compromise—two malicious npm packages (now removed) that downloaded from C2 and attributed to North Korean actor Sapphire Sleet—potentially exposed hundreds to millions of users; guidance for detecting and responding to a Trivy distribution compromise that injected credential‑stealing malware into CI/CD pipelines worldwide; a WhatsApp‑delivered campaign using VBScript and cloud‑hosted payloads to install MSI backdoors; and additional advisories on the

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
3f4fe0301dd174cd00c633d48d9e333c66f5b604e93547e6698b93c1a6d62591
Enrichment time
2026-04-02T02:52:23Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.