Secure What Matters: Scaling Effortless Container Security for the AI Era
2026-04-09T20:52:08Z•dd1a94609d61b717142d8837a6fc2913060a60733bbdd7885db9bcbdd2532fd3
axioscompromised-maintainerdependency-injectiondetectionincident-responsemalicious-packagemalwaremitigationnpmpackage-integrityremote-access-trojansoftware-supply-chainsupply-chaintransitive-dependency
What happened
Snyk reports a malicious supply-chain compromise of the popular Axios npm package: attacker-controlled maintainer account published malicious versions 1.14.1 and 0.30.4 that add a hidden dependency deploying a cross-platform remote-access trojan (RAT). The incident can impact any projects that pull those package versions or transitive dependencies; Snyk provides guidance to detect exposure, remove or pin to safe versions, audit dependency and CI secrets, and investigate potential compromise. No CVE identifiers were listed in the blog post.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- snyk_blog
- Record identifier
- dd1a94609d61b717142d8837a6fc2913060a60733bbdd7885db9bcbdd2532fd3
- Enrichment time
- 2026-04-09T20:52:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.