Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT

2026-03-31T20:52:02Zd020923691bd51d663afc82559f164ebeec54621bd18c3d5cfb9e0e1634fcc7e
CI/CD-compromisePyPIRATTrivyaxiosbackdoorcompromised-maintainerlitellmmalicious-packagenpmremote-access-trojansoftware-supply-chainsupply-chainteamPCP

What happened

Snyk reported multiple recent supply-chain incidents. Most notably, malicious Axios npm releases (1.14.1 and 0.30.4) were published from a compromised maintainer account; those packages add a hidden dependency that installs a cross-platform remote‑access trojan (RAT). Separately, TeamPCP published backdoored versions of the litellm PyPI package after stealing PyPI credentials via a compromised Trivy GitHub Action in LiteLLM’s CI/CD, using a multi-stage malware/backdoor chain. Organizations should treat this as an active supply‑chain compromise: identify and remove the malicious package(s), pin

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
snyk_blog
Record identifier
d020923691bd51d663afc82559f164ebeec54621bd18c3d5cfb9e0e1634fcc7e
Enrichment time
2026-03-31T20:52:02Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT · Baitaphish