MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Axios npm account compromise distributes malicious package versions

A compromised Axios maintainer account was used on 31 March 2026 to publish malicious npm versions 1.14.1 and 0.30.4. The poisoned releases added plain-crypto-js 4.2.1, whose install hook deployed a cross-platform remote access trojan. The malicious Axios versions were available for about three hours before removal, creating a software-supply-chain compromise for downstream projects that installed them. Google Threat Intelligence attributed the activity to North Korea-nexus actor UNC1069.

74

Estimated severity

74 / 100

98

Source reliability

98 / 100

Approximate Date

31/03/2026

Targeted Company

AXIOS

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

Country visual unavailable

No information

Other Affected Countries

No other affected countries reported

Target country

No information

Affected countries

No information

Impacted regions

No information

Operational Impact

Duration

0.13 days

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impact

Affected sectors

Technology & IT Services

Affected departments

Information TechnologyDistribution & Fulfillment

Attack Profile

Attack types

Account takeoverSoftware supply chain compromiseRemote access trojan

Attributed threat actors

UNC1069

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.