Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT
2026-03-31T20:52:02Z•d020923691bd51d663afc82559f164ebeec54621bd18c3d5cfb9e0e1634fcc7e
CI/CD-compromisePyPIRATTrivyaxiosbackdoorcompromised-maintainerlitellmmalicious-packagenpmremote-access-trojansoftware-supply-chainsupply-chainteamPCP
What happened
Snyk reported multiple recent supply-chain incidents. Most notably, malicious Axios npm releases (1.14.1 and 0.30.4) were published from a compromised maintainer account; those packages add a hidden dependency that installs a cross-platform remote‑access trojan (RAT). Separately, TeamPCP published backdoored versions of the litellm PyPI package after stealing PyPI credentials via a compromised Trivy GitHub Action in LiteLLM’s CI/CD, using a multi-stage malware/backdoor chain. Organizations should treat this as an active supply‑chain compromise: identify and remove the malicious package(s), pin
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- snyk_blog
- Record identifier
- d020923691bd51d663afc82559f164ebeec54621bd18c3d5cfb9e0e1634fcc7e
- Enrichment time
- 2026-03-31T20:52:02Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.