Supply chain attack on Axios npm package: Scope, impact, and remediations
2026-03-31T20:52:17Z•fcad1b9e1a49457850c51084836c14a900ede0a5f7d65f49c019113faf5ee35c
axioscredential-theftincident-responsejavascriptlockfile-auditmalicious-dependencynpmpackage-pinningplain-crypto-jsremediationsoftware-supply-chainsupply-chain
What happened
Tenable confirmed a software supply‑chain compromise of the popular Axios npm package: attackers hijacked a maintainer account and published malicious Axios releases (noted versions 1.14.1 and 0.30.4) that introduce a hidden malicious dependency called “plain-crypto-js.” Any environment that pulled those versions is at high risk of credential and API‑key theft and other severe data exfiltration. Immediate actions: scan for and identify hosts/artifacts containing the compromised versions or dependency (package.json, lockfiles, node_modules, SBOMs, artifact registry logs), quarantine affected bl
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- tenable_blog
- Record identifier
- fcad1b9e1a49457850c51084836c14a900ede0a5f7d65f49c019113faf5ee35c
- Enrichment time
- 2026-03-31T20:52:17Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.