Secure What Matters: Scaling Effortless Container Security for the AI Era
2026-04-08T20:51:59Z•c72740c32e3c7f07213d8c5edffe82fc8639389a04e58748b7dbd6f0f80863a3
RATaxiosdependency-injectiondetectionincident-responsemaintainer-compromisemalwarenpmremediationremote-access-trojansoftware-supply-chain-attacksupply-chain
What happened
Snyk reports a malicious supply-chain compromise of the Axios npm package: attackers published trojanized versions 1.14.1 and 0.30.4 via a compromised maintainer account that introduced a hidden dependency which deploys a cross-platform remote access trojan (RAT). The compromise affects projects that depend on those specific versions (directly or transitively); Snyk’s post explains impact, detection steps, and how to check exposure and remediate. No CVE identifiers were referenced in the blog post.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- snyk_blog
- Record identifier
- c72740c32e3c7f07213d8c5edffe82fc8639389a04e58748b7dbd6f0f80863a3
- Enrichment time
- 2026-04-08T20:51:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.