
Security Advisory: npm axios Supply Chain Compromise
A recent npm supply chain compromise tied to axios has turned a routine dependency update into a vulnerability. On March 31, 2026, attackers used a compromised maintainer account to publish two malicious axios versions, 1.14.1 and 0.30.4. Those releases pulled in a hidden dependency called plain-crypto-js, which dropped a remote access trojan during installation on macOS, Windows, and Linux. In Huntress’s early response, the company reported at least 135 endpoints in its partner base contacting

















