Back to Intel

Intel Node

Axios NPM supply chain incident

lowmalware2026-04-03T17:00:22+00:00source excerpt
malwarewindowslinux

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

Overview of the recent Axios NPM supply chain incident including details of the payloads delivered from actor-controlled infrastructure.

Cisco Talos is actively investigating the March 31, 2026 supply chain attack on the official Axios node package manager (npm) package during which two malicious versions (v1. 14. 1 and v0. 30. 4) were deployed. Axios is one of the more popular JavaScript libraries with as many as 100 million downloads per week. Axios is a widely-deployed HTTP client library for JavaScript that simplifies HTTP requests, specifically for REST endpoints. The malicious packages were only available for approximately three hours, but if downloaded Talos strongly encourages that all deployments should be rolled back to previous known safe versions (v1. 14.

0 or v0. 30. 3). Additionally, Talos strongly recommends users and administrators investigate any systems that downloaded the malicious package for follow-on payloads from actor-controlled infrastructure.

Read Original Source