Axios NPM Distribution Compromised in Supply Chain Attack
A compromised axios maintainer account led to malicious npm releases affecting projects with active dependencies on the package. The incident involved unauthorized releases propagated through the npm distribution network.
- Disclosed
- Last updated
- Blast radius
- axios npm package and all projects with active dependencies
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- axios
A compromised axios maintainer account led to malicious npm releases that propagated across environments. According to the report, the attacker gained control of an axios maintainer account and used it to publish unauthorized malicious versions to npm.\n\nThe malicious releases reached projects with active dependencies on axios, creating a broad attack surface across the JavaScript ecosystem. The specific technical details of the payload and the exact versions affected are not provided in this source text.\n\nDetection and remediation guidance has been published by Wiz to help organizations assess impact, detect compromise, and secure their development workflows. Organizations using axios should review their dependency versions and apply security patches.
Remediation
- Review all axios dependencies and identify currently installed versions
- Update axios to the latest patched version from npm
- Audit project logs for evidence of code execution from malicious axios releases
- Implement dependency integrity checking and lock file verification
- Enable account security features for npm maintainer accounts including 2FA
- Review and revoke any suspicious API tokens or credentials
Sources
- Axios NPM Distribution Compromised in Supply Chain Attack · Wiz
- North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack · Google Threat Intelligence Group
Cite this entry
"Axios NPM Distribution Compromised in Supply Chain Attack." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed March 31, 2026; last updated June 7, 2026. https://supplychainattack.org/incident/axios-npm-distribution-compromised-in-supply-chain-attack-81wu4e
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in @antv/gi-assets-basic (npm)
A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/gi-assets-basic, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g2-ssr (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g2-ssr, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g6-extension-3d (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g6-extension-3d, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in gantt-for-react (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including gantt-for-react, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit