Secure What Matters: Scaling Effortless Container Security for the AI Era

2026-04-08T20:51:59Zc72740c32e3c7f07213d8c5edffe82fc8639389a04e58748b7dbd6f0f80863a3
RATaxiosdependency-injectiondetectionincident-responsemaintainer-compromisemalwarenpmremediationremote-access-trojansoftware-supply-chain-attacksupply-chain

What happened

Snyk reports a malicious supply-chain compromise of the Axios npm package: attackers published trojanized versions 1.14.1 and 0.30.4 via a compromised maintainer account that introduced a hidden dependency which deploys a cross-platform remote access trojan (RAT). The compromise affects projects that depend on those specific versions (directly or transitively); Snyk’s post explains impact, detection steps, and how to check exposure and remediate. No CVE identifiers were referenced in the blog post.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
snyk_blog
Record identifier
c72740c32e3c7f07213d8c5edffe82fc8639389a04e58748b7dbd6f0f80863a3
Enrichment time
2026-04-08T20:51:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.