CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly Downloads

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6227

As cited

Copy frozen at (site build).

vulnerabilities

Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly Downloads

Attackers used compromised npm credentials to publish malicious versions of the widely used Axios HTTP client library. The poisoned packages installed a remote access trojan (RAT) that executed during setup, while the library's legitimate files were replaced with clean decoys to evade detection.

Why it matters: JavaScript developers and organizations using Axios across projects face immediate risk of system compromise; practitioners should audit npm dependencies, check installation logs, and review the npm security advisory for affected versions and remediation steps.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary