Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT

2026-04-01T08:51:59Z6e7fa1089750d0022ab42d3367212671a834de1aa3fcd2aaf5102750e0d7eadc
RATaxioscompromised-maintainerdependency-injectionmalwarenodejsnpmpackage-securitysupply-chain

What happened

Snyk reports a supply-chain attack in which a compromised maintainer account published malicious Axios npm package versions (1.14.1 and 0.30.4) that add a hidden dependency which deploys a cross-platform remote access trojan (RAT). Projects that depend directly or transitively on those Axios versions may be exposed; Snyk guidance covers how to detect affected projects and remediate (rollback to clean versions, inspect lockfiles/builds, rotate credentials, and follow advisories).

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
snyk_blog
Record identifier
6e7fa1089750d0022ab42d3367212671a834de1aa3fcd2aaf5102750e0d7eadc
Enrichment time
2026-04-01T08:51:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT · Baitaphish