Axios npm package compromised in supply chain attack

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Socket Research Team disclosed the attack, with analysis showing the malicious package deploys a multi-stage payload including a remote access trojan, contradicting the framing of a simple typosquat or single-stage compromise
- Axios versions 1.14.1 and 0.30.4 were compromised via a maintainer account hijack, per GitHub issue #10604 on the axios/axios repository, which means any project that pulled the update in the window is potentially exposed
- Step Security, BleepingComputer, The Hacker News, Tom's Hardware, The Register, and Bloomberg all confirmed the cross-platform RAT payload, with download-count estimates ranging from 100M weekly to 300M–400M monthly depending on outlet
- Security Boulevard flagged that the RAT 'vanishes after install,' a detail the dominant 'supply chain attack' framing tends to flatten — meaning post-install detection is harder than the headline suggests
- Salesforce Ben published specific guidance for Salesforce developers, and r/ClaudeAI threads warned users who 'vibe coded' with the package — the attack's blast radius extends well beyond backend Node.js shops
- Aikido Security and Koi characterized it as a maintainer account takeover rather than a malicious package publish, pointing at upstream credential theft as the actual root cause
Why it matters: Axios sits inside the build pipelines of an enormous share of JavaScript projects (100M+ weekly downloads), so a hijacked maintainer account effectively delivered a cross-platform RAT to developer machines at scale, and the RAT's reported ability to vanish after install means downstream detection will lag the initial infection window.




