Axios npm Package Compromised in Supply Chain Attack
Axios npm package compromised in significant supply chain attack.

The npm ecosystem faced a significant security breach on March 31, 2026, when two versions of Axios, a popular HTTP client library with over 100 million weekly downloads, were found to contain a Remote Access Trojan. The compromised versions, axios@1.14.1 and axios@0.30.4, were published through a hijacked maintainer account, reaching many developer environments before being removed. Security researchers quickly flagged the attack, which involved a malicious transitive dependency that had been seeded as a clean typosquat of a legitimate library.
Key Takeaways
- 1.
Axios versions 1.14.1 and 0.30.4 were found to contain a Remote Access Trojan.
- 2.
The malicious package was identified within six minutes of its appearance on npm.
- 3.
Projects using unpinned dependencies were particularly vulnerable to this attack.
Get your personalized feed
Trace groups the biggest stories, videos, and discussions into one feed so you can stay current without scanning ten tabs.
Try Trace free