Skip to main content

Share story

Security

Axios NPM Package Compromised, Malicious Versions Dropping Remote Access Trojan

The Axios JavaScript library, one of the most widely downloaded packages on the npm registry with hundreds of millions of weekly downloads, has been compromised with malicious versions that drop a Remote Access Trojan onto affected systems, according to reporting surfaced on Hacker News Monday. Axios is a promise-based HTTP client for JavaScript used extensively in web applications and Node.js back-end services. Its ubiquity in the JavaScript ecosystem makes the compromise a significant supply chain security event, as developers who install affected versions or whose automated dependency updates pull them in could silently expose their systems to attacker-controlled malware. A Remote Access Trojan, or RAT, gives attackers persistent remote control over an infected machine, typically including the ability to exfiltrate files, capture keystrokes, access credentials stored in browsers or environment variables, and execute arbitrary commands. In a development environment, a RAT could expose source code, API keys, cloud credentials, and access to internal networks. The attack follows a well-established pattern of npm supply chain compromises in which attackers either take over a legitimate package account, publish typosquat packages with similar names, or introduce malicious code through a dependency update. High-profile prior incidents include the compromise of the ua-parser-js package in 2021 and the event-stream incident in 2018. Developers using Axios were urged to verify the integrity of installed versions against the official package and to check for unexpected processes or outbound network connections on affected systems. The specific compromised version numbers and whether the malicious code had been removed from the registry were not immediately confirmed in initial reports. The Axios maintainers had not issued a public statement at time of publication.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Products Capital
Products Capital

Numeral raises $100M for sales tax automation

Numeral raised a $100M Series C led by Insight Partners, FinTech Global reported. Its AI-powered platform automates sales tax compliance workflows in over 90 countries. The financing adds capital to a business serving companies t...

Capital Products
Capital Products

HIFI raises $37M for stablecoin payment infrastructure

HIFI raised a $37M Series A led by Left Lane Capital, The Block reported. The New York City company provides software interfaces for stablecoin payments and settlements, giving businesses a way to connect those transactions to the...

Infrastructure Capital
Infrastructure Capital

PicoJool raises $27.5M for AI data center interconnects

PicoJool raised a $27.5M Series A led by Socratic Partners, SiliconANGLE reported. The startup is developing interconnects for AI data centers based on vertical cavity surface emitting lasers. Former Intel chief executive Pat Gel...

Security Infrastructure
Security Infrastructure

Two unpatched NetScaler flaws reportedly exploited in attacks

Security firm watchTowr says attackers have exploited two previously undisclosed flaws that could allow remote code execution on Citrix NetScaler appliances. The firm said it identified the flaws during forensic investigations and...

Security Products
Security Products

Flock seeks removal of map showing 335,701 camera locations

Flock has sought to take down a researcher's website that maps 335,701 of its cameras, Tom's Hardware reports. A company acting on Flock's behalf filed a trademark complaint over the site's use of the Flock Safety name. Researche...