Threat Brief: Widespread Impact of the Axios Supply Chain Attack

Reported 01 Apr 2026 by otx · Severity: medium

A sophisticated supply chain attack compromised the Axios JavaScript library after threat actors hijacked an npm maintainer account, releasing malicious versions v1.14.1 and v0.30.4. These versions contained a hidden dependency called plain-crypto-js, which deployed a cross-platf