Secure What Matters: Scaling Effortless Container Security for the AI Era

2026-04-09T20:52:08Zdd1a94609d61b717142d8837a6fc2913060a60733bbdd7885db9bcbdd2532fd3
axioscompromised-maintainerdependency-injectiondetectionincident-responsemalicious-packagemalwaremitigationnpmpackage-integrityremote-access-trojansoftware-supply-chainsupply-chaintransitive-dependency

What happened

Snyk reports a malicious supply-chain compromise of the popular Axios npm package: attacker-controlled maintainer account published malicious versions 1.14.1 and 0.30.4 that add a hidden dependency deploying a cross-platform remote-access trojan (RAT). The incident can impact any projects that pull those package versions or transitive dependencies; Snyk provides guidance to detect exposure, remove or pin to safe versions, audit dependency and CI secrets, and investigate potential compromise. No CVE identifiers were listed in the blog post.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
snyk_blog
Record identifier
dd1a94609d61b717142d8837a6fc2913060a60733bbdd7885db9bcbdd2532fd3
Enrichment time
2026-04-09T20:52:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Secure What Matters: Scaling Effortless Container Security for the AI Era · Baitaphish