This is a reference source. Read the analysis on our homepage.
Home
axios Compromised on npm - Malicious Versions Drop Remote Access Trojan - StepSecurity
AAdmin
31 tháng 3, 2026
1 min read
Source: Hacker News
Hijacked maintainer account used to publish poisoned axios releases including 1.14.1 and 0.30.4. The attacker injected a hidden dependency that drops a cross platform RAT. We are actively investigating and will update this post with a full technical analysis.
Hijacked maintainer account used to publish poisoned axios releases including 1.14.1 and 0.30.4. The attacker injected a hidden dependency that drops a cross platform RAT. We are actively investigating and will update this post with a full technical analysis.