Axios compromised: supply chain attack spread malware on Windows, macOS and Linux
Axios is among the most widely used HTTP clients in the JavaScript ecosystem, with tens of millions up to approximately 100 million downloads per week.

Compromise via maintainer's npm account
Axios is among the most widely used HTTP clients in the JavaScript ecosystem, with tens of millions up to approximately 100 million downloads per week.
At the turn of March 30 and 31, 2026, the npm account of one of the main maintainers was compromised. The attacker then published two malicious versions of the package:
axios@1.14.1axios@0.30.4
These versions were available for only a few hours before being removed from the registry.
Attack via dependency, not via Axios itself
Crucially, according to analyses, the Axios source code itself was not directly malicious.
Instead, the attackers added a new dependency:
plain-crypto-js@4.2.1
This library was not used anywhere in the project. Its sole purpose was to run a postinstall script during package installation.
During a regular npm install command, the dropper was automatically executed, which then downloaded and ran the malware.
What the malware did
The deployed malware was a RAT (Remote Access Trojan), a tool for remotely controlling a system.
After execution it performed:
- system reconnaissance (files, processes, environment)
- communication with a command-and-control server (C2)
- regular polling for instructions (approximately every 60 seconds)
This allowed the attacker to execute commands on the compromised device, browse files, or deploy additional malicious code.
Multiplatform attack
The attack was designed to be fully cross-platform.
On macOS, a binary was downloaded to /Library/Caches/com.apple.act.mond and executed in the background. The variant was written in C++ and regularly communicated with the C2 server.
In Windows environments, the malware used PowerShell, masqueraded as a legitimate system tool, and created a persistence mechanism that ensured it would run after logon.
On Linux a Python script was deployed and run in the background without persistence, which suggests more short-term use.
All variants shared the same communication protocol and command set.
Evading detection
The attack was designed to minimize the chance of detection.
The malicious code was not part of Axios itself but in a dependency that executed automatically during installation. Furthermore, it was not imported anywhere, so it did not appear suspicious during a routine code review.
After execution, the malware removed the install script and overwrote the package's configuration files to make it look legitimate.
This significantly complicated forensic analysis.
Prepared and targeted attack
Analysis shows this was not a random incident.
The malicious dependency was published in advance, payloads existed for all major platforms, and the compromised Axios versions were deployed in a short time window of a few hours.
The attacker likely obtained a long-lived access token for the npm account, allowing them to publish packages outside the standard CI/CD process.
Possible attribution
According to analysis by the Google Threat Intelligence Group, the attack shows similarities to the WAVESHAPER malware, which was previously associated with the North Korean group UNC1069.
This attribution is based on technical similarities and is not officially confirmed.
Recommendations
Organizations should:
- check whether versions
1.14.1or0.30.4were used - remove the
plain-crypto-jspackage - upgrade to safe versions (
1.14.0,0.30.3)
Also check for possible artifacts:
- macOS:
/Library/Caches/com.apple.act.mond - Windows:
%PROGRAMDATA%\\wt.exe - Linux:
/tmp/ld.py
If found, the system should be considered compromised and all credentials rotated.
Wider impact
The incident demonstrates that security today relies not only on reviewing your own code, but on trust in the entire supply chain.
Compromising a single account or dependency is enough for an attack to affect a large number of projects.
Summary
Axios was compromised via a maintainer's npm account. The attackers added a malicious dependency that launched a cross-platform RAT malware during installation.
The attack was short-lived, technically sophisticated, and designed to minimize detection.