Daily Dark Web
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
Daily Dark Web
No Result
View All Result
Home Vulnerability

Axios npm Package Compromised in Supply Chain Attack

🇺🇸 United States - Axios

March 31, 2026
Reading Time: 1 min read
Axios npm Package Compromised in Supply Chain Attack

Axios, the widely used open-source JavaScript HTTP client library with over 100 million weekly downloads, has suffered a critical software supply chain attack. An unidentified threat actor hijacked the npm account of a lead maintainer (jasonsaayman), bypassing the project’s standard GitHub Actions CI/CD pipeline to manually publish two poisoned versions: [email protected] and [email protected]. These malicious releases injected a fake dependency named [email protected], which utilizes a heavily obfuscated postinstall script to act as a cross-platform remote access trojan (RAT) dropper. Targeting macOS, Windows, and Linux systems, the malware automatically executes to download platform-specific stage-2 payloads from an external command-and-control server (sfrclak.com), subsequently overwriting its own package.json file and deleting its tracks to evade post-incident forensic detection.

The allegedly compromised data and impacted assets on exposed developer machines and CI/CD environments include:

  • Maintainer npm account credentials

  • Developer workstation credentials

  • SSH private keys

  • Cloud environment access tokens (AWS, GCP, Azure)

  • CI/CD pipeline secrets

  • .env file contents

Tags: AxiosCyberSecuritymalwarenpmOpen SourceRATsupply-chain attackUnited States
ShareTweet

Related Posts

CPUID Website Compromised: CPU-Z and HWMonitor Serve Malware
Vulnerability

CPUID Website Compromised: CPU-Z and HWMonitor Serve Malware

April 10, 2026
Critical Figma MCP Server Flaw Allows Remote Code Execution
Vulnerability

Critical Figma MCP Server Flaw Allows Remote Code Execution

October 8, 2025
Oracle Patches CVE−2025−61882
Vulnerability

Oracle Patches CVE−2025−61882

October 6, 2025
Shai-Hulud Worm Infects Over 500 NPM Packages in Sophisticated Supply Chain Attack
Vulnerability

Shai-Hulud Worm Infects Over 500 NPM Packages in Sophisticated Supply Chain Attack

September 17, 2025
WinRAR Zero-Day RCE Vulnerability Allegedly for Sale for $65,000
Vulnerability

WinRAR Zero-Day RCE Vulnerability Allegedly for Sale for $65,000

September 8, 2025
Atomic and Exodus Crypto Wallets at Risk from Deceptive npm Package
Vulnerability

Atomic and Exodus Crypto Wallets at Risk from Deceptive npm Package

September 2, 2025
Next Post
KaleaMarket Data Breach Exposes Information of 20,000 Users

KaleaMarket Data Breach Exposes Information of 20,000 Users

AVC-Livestock Data Breach Exposes Afghan Supply Chain Users

AVC-Livestock Data Breach Exposes Afghan Supply Chain Users

Recommended Stories

CRRC MA America Data Breach Exposes Critical Transit Schematics

CRRC MA America Data Breach Exposes Critical Transit Schematics

December 8, 2025
BehMusic Data Breach Exposes 257k User Records

BehMusic Data Breach Exposes 257k User Records

January 19, 2026
Full ‘New American Funding’ Data Leaked by Everest After Failed Ransom Negotiations

Full ‘New American Funding’ Data Leaked by Everest After Failed Ransom Negotiations

July 24, 2025

Popular Stories

  • SudamericaData Breach Exposes Over 1TB of Argentine Records

    SudamericaData Breach Exposes Over 1TB of Argentine Records

    0 shares
    Share 0 Tweet 0
  • Threat Actor Claims Sale of Dell Database Containing 49 Million Customer Records

    0 shares
    Share 0 Tweet 0
  • SUUMO, CHINTAI, At Home, HOME’S Suffer Data Breach

    0 shares
    Share 0 Tweet 0
  • Financial Tech Giant SilverLake Axis Allegedly Breached – 423GB of Data for Sale

    0 shares
    Share 0 Tweet 0
  • Telekom Serbia Investigates Leak of 160,000 Customer Records

    0 shares
    Share 0 Tweet 0
Daily Dark Web

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

No Result
View All Result
  • About Us
  • Home
  • Newsletter
  • Privacy Policy

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?