Country visual unavailable
No information
A compromised Axios maintainer account was used on 31 March 2026 to publish malicious npm versions 1.14.1 and 0.30.4. The poisoned releases added plain-crypto-js 4.2.1, whose install hook deployed a cross-platform remote access trojan. The malicious Axios versions were available for about three hours before removal, creating a software-supply-chain compromise for downstream projects that installed them. Google Threat Intelligence attributed the activity to North Korea-nexus actor UNC1069.
Estimated severity
74 / 100
Source reliability
98 / 100
Approximate Date
31/03/2026
Targeted Company
AXIOS
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
Country visual unavailable
No information
No other affected countries reported
Target country
No information
Affected countries
No information
Impacted regions
No information
Duration
0.13 days
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
Incident Sources
Please rotate your phone