Supply Chain Attack Hits Axios NPM Packages
Axios is a dependency in nearly 80% of all cloud and code environments and sees approximately 100 million downloads per week.

Axios is a dependency in nearly 80% of all cloud and code environments and sees approximately 100 million downloads per week.
April 1, 2026 | 4 min read

UPDATE--A significant supply chain attack has hit the immensely popular axios npm package, leading to the installation of a small RAT on victim machines. For a brief, critical window of a few hours on Tuesday morning, a threat actor compromised a maintainer's npm account and published two malicious versions of the package (v1.14.1 and v0.30.4).
Given that axios is a dependency in nearly 80% of all cloud and code environments and sees approximately 100 million downloads per week, this intrusion represents a serious concern for the community despite the limited window of exposure for the compromised packages. Even with a quick takedown, the short exposure window was enough to result in observed execution of the trojanized package in 3% of affected environments, according to researchers at Wiz.
Google's Threat Intelligence Group has attributed this attack to a North Korean actor it calls UNC1069 that has a history of intrusions focused on cryptocurrency heists. The attirbution is based in part on the deployment of a backdoor called Waveshaper.v2, which is a direct descendant of a piece of malware this group has used in the past.
"Analysis of the C2 infrastructure (sfrclak[.]com resolving to 142.11.206.73) revealed connections from a specific AstrillVPN node previously used by UNC1069. Additionally, adjacent infrastructure hosted on the same ASN has been historically linked to UNC1069 operations," the Google analysis says.
The attacker was able to compromise the GitHub and npm accounts of one of the maintainers of axios in the early morning hours Tuesday and then added a trojanized package called plain-crypto-js as a dependency to the two compromised versions.
The axios maintainers have removed the compromised packages. Axios is ubiquitous and is deployed so widely that it is essentially a load-bearing part of the web ecosystem.
“When the attack first happened, Axios maintainers were unable to regain control of the project. In a public GitHub issue, a collaborator stated they could not revoke access from the account responsible for the malicious publish, noting that the attacker’s permissions exceed their own,” researchers at Socket said in a comprehensive analysis of the incident.
The Socket team said there is no indication right now that the axios intrusion is related to the recent TeamPCP supply chain attacks.
“The malicious package includes a dropper (setup.js) that downloads and executes platform-specific second-stage payloads from sfrclak.com:8000, and then self-cleans by deleting itself and restoring a clean package.json. The second-stage payloads function as lightweight remote access trojans (RATs) and beacon to the C2 server every 60 seconds, transmitting system inventory and awaiting commands,” the Wiz analysis says.
“All three variants implement similar capabilities, including remote shell execution, binary injection, directory browsing, process listing, and system reconnaissance, while differing by operating system.”
Infection Chain:
Payload Capabilities
The ultimate payloads, which functioned as lightweight RATs, were designed for full system reconnaissance and control.The RAT gave the attacker several capabilities on target systems, including remote shell execution, binary injection, data exfiltration, and system reconnaissance. After execution, the malware deletes itself and takes other actions to eliminate traces on compromised machines.
Platform Specifics
| OS | Payload Details | Persistence/Evasion |
| macOS | C++ compiled Mach-O universal binary. | Capable of self-signing injected payloads via codesign. |
| Windows | PowerShell script. | Achieved persistence via a registry Run key (MicrosoftUpdate) and a re-download batch file. |
| Linux | Delivered as a Python script. | Focused on system inventory and remote control. |
Immediate Action Required
Due to the high-stakes nature of this attack, all organizations and individual developers must assume potential exposure and perform an immediate security audit when possible.
1. Audit Dependencies Now
The highest priority is to search your codebase and deployment environments for the following malicious versions:
If either of these versions is found in any of the package-lock.json, yarn.lock, or running applications, treat the affected environment as compromised.
2. Isolate and Scan
If a malicious version was executed in your environment:
3. Reference the Official Advisories
Track this vulnerability using the official advisories for a complete list of IoCs and real-time updates:
For ongoing updates about the intrusion and the downstream effects, keep an eye on the Socket blog and Huntress blog.
This story was updated on April 1 to add attribution information from Google.
April 1, 2026 | 4 min read
Dennis Fisher is an award-winning journalist and author. He is one of the co-founders of Decipher and Threatpost and has been writing about cybersecurity since 2000. Dennis enjoys finding the stories behind the headlines and digging into the motivations and thinking of both defenders and attackers. He is the author of 2.5 novels and once met Shaq. Contact: dennis at decipher.sc.