Supply chain attack on Axios npm package: Scope, impact, and remediations

2026-03-31T20:52:17Zfcad1b9e1a49457850c51084836c14a900ede0a5f7d65f49c019113faf5ee35c
axioscredential-theftincident-responsejavascriptlockfile-auditmalicious-dependencynpmpackage-pinningplain-crypto-jsremediationsoftware-supply-chainsupply-chain

What happened

Tenable confirmed a software supply‑chain compromise of the popular Axios npm package: attackers hijacked a maintainer account and published malicious Axios releases (noted versions 1.14.1 and 0.30.4) that introduce a hidden malicious dependency called “plain-crypto-js.” Any environment that pulled those versions is at high risk of credential and API‑key theft and other severe data exfiltration. Immediate actions: scan for and identify hosts/artifacts containing the compromised versions or dependency (package.json, lockfiles, node_modules, SBOMs, artifact registry logs), quarantine affected bl

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
tenable_blog
Record identifier
fcad1b9e1a49457850c51084836c14a900ede0a5f7d65f49c019113faf5ee35c
Enrichment time
2026-03-31T20:52:17Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.