Supply-Chain Compromise of axios npm Package
Reported 31 Mar 2026 by otx · Severity: medium
A coordinated supply chain attack targeted the axios npm package, compromising two versions (1.14.1 and 0.30.4) by injecting a malicious dependency. The attack delivered a cross-platform Remote Access Trojan to macOS, Windows, and Linux systems. The compromise occurred through th