The Axios library was attacked through a supply chain, with hackers using stolen npm tokens to implant a remote trojan, affecting about 80% of cloud environments

By: rootdata|2026/04/02 13:48:26
0
Share
copy

The attacker stole the npm access token of the chief maintainer of Axios, the most popular HTTP client library for JavaScript, and used that token to publish two malicious versions containing cross-platform remote access trojans (RATs) (axios@1.14.1 and axios@0.3.4), targeting macOS, Windows, and Linux systems. The malicious packages were removed from the npm registry about 3 hours after being published.

According to data from security company Wiz, Axios is downloaded over 100 million times weekly and exists in about 80% of cloud and code environments. Security company Huntress detected the first infections just 89 seconds after the malicious packages went live and confirmed that at least 135 systems were compromised during the exposure window. Notably, the Axios project had previously deployed modern security measures such as OIDC trusted publishing mechanisms and SLSA provenance proofs, but the attacker completely bypassed these defenses. Investigations revealed that while configuring OIDC, the project retained the traditional long-lived NPM_TOKEN, and npm defaults to using the traditional token when both coexist, allowing the attacker to publish without breaching OIDC.

-- Price

--

You may also like

Champion's Final Bow: FC Barcelona vs Real Betis – Celebrate the Title with a Home Finale

FC Barcelona are champions! After beating Real Madrid to clinch the 2025-26 LALIGA title, Barça return home to face Real Betis on May 17. A victory party at Spotify Camp Nou awaits. Full preview inside.

Best Oil Trading Platform for Crypto Users in 2026

Looking for the best oil trading platform for crypto users? Trade crude oil, gold, forex, and US stock futures directly with USDT on WEEX TradFi with 0% trading fees and no broker account required.

5 Futures Trading Strategies Smart Traders Use to Cut Crypto Fees and Boost Futures Returns

Most futures traders focus on entries and exits but ignore the fees quietly killing profits. Learn 5 futures trading strategies to cut costs and improve returns in 2026.

What Is TradFi? How Crypto Traders Can Now Access Crude Oil, Gold, and Global Markets

What is TradFi in crypto? Learn how crypto traders can now trade crude oil, gold, stocks, and global markets directly with USDT on WEEX TradFi with 0 fee trading and a $150,000 bonus pool.

How WEEX Bridges Crypto and Football: A Deep Look at the LALIGA Partnership Inside the WEEX App

WEEX is not just a LALIGA sponsor. It’s a true partner. From iPhone Dynamic Island to LALIGA-themed app icons and smart posters, see how WEEX brings football passion into every trade — and builds a real bridge between crypto and sports.

FC Barcelona vs Real Madrid Preview: El Clásico – Can Barça Clinch the Title at Spotify Camp Nou?

FC Barcelona vs Real Madrid El Clásico match preview for May 11, 2026. Barça need just 1 point to win LALIGA. Can Madrid delay the trophy? Full preview inside.

Contents

Popular coins

Latest Crypto News

Read more
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com