Attackers hijacked the npm account of Axios maintainer Jason Saayman and published malicious axios@1.14.1 and axios@0.30.4, bypassing the project’s normal GitHub Actions OIDC publishing flow and adding the staged dependency plain-crypto-js@4.2.1. That package’s postinstall logic fetched platform-specific payloads from sfrclak[.]com:8000, deploying a remote access trojan on Windows, macOS, and Linux while deleting installer artifacts and restoring benign-looking package metadata to hinder detection. The poisoned releases were available for roughly three hours before removal, but Axios’s massive downstream use meant developer workstations, CI/CD pipelines, ephemeral builds, and transitive dependencies could all have resolved the malicious versions during the exposure window.
Researchers and vendors including Socket, StepSecurity, Elastic, Huntress, Microsoft, Google Threat Intelligence Group, and others said affected systems should be treated as fully compromised because the malware enabled reconnaissance, command execution, persistence on Windows, payload retrieval, and likely credential theft. Multiple reports tied the operation to a North Korea-linked actor—most prominently UNC1069, with other vendors using names such as Sapphire Sleet and STARDUST CHOLLIMA—while Axios later confirmed the maintainer had been compromised through a targeted social-engineering campaign involving fake corporate outreach and a bogus meeting workflow. Organizations were urged to roll back to safe versions such as 1.14.0 or 0.30.3, remove plain-crypto-js, rebuild impacted hosts, rotate all accessible secrets, review lockfiles and CI logs, and block traffic to the identified command-and-control infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
18 events from the most recent confirmed update back to the earliest known activity.
CISA published an alert about the Axios npm compromise, identifying it as a supply-chain attack involving a malicious dependency introduced into Axios updates. The advisory primarily pointed organizations to the Axios post-mortem and Microsoft's mitigation guidance.
OpenAI said its GitHub Actions workflow automatically downloaded and executed malicious Axios on March 31, exposing macOS signing and notarization materials used for ChatGPT Desktop, Codex, Atlas, and Codex CLI. The company said no user data or internal systems were compromised, but it revoked and rotated affected certificates as a precaution.
Socket described a coordinated social engineering campaign targeting multiple high-impact Node.js and npm maintainers beyond Axios, using fake outreach, spoofed workspaces, and malware lures. The article tied the tradecraft to DPRK-nexus activity tracked as UNC1069.
Jason Saayman publicly confirmed the incident resulted from a targeted social engineering attack in which an attacker impersonated a legitimate company and hijacked authenticated sessions after gaining access to his machine. He said he wiped devices, reset credentials, and began adopting stronger protections afterward.
Axios disclosed a post-mortem stating that malicious npm releases 1.14.1 and 0.30.4 were published on March 31, 2026 after the maintainer was compromised through targeted social engineering and RAT malware. The project said maintainer devices were wiped, credentials reset, and security improvements such as immutable releases and OIDC-based publishing were being implemented.
Axios maintainer Jason Saayman later said attackers impersonated a legitimate company, used a fake Slack workspace and meeting flow, and gained access to his machine and authenticated sessions. This enabled theft or abuse of npm and GitHub access needed for the package compromise.
Microsoft Threat Intelligence said the malicious Axios releases were published on March 31, 2026 and attributed the operation to the North Korean state actor Sapphire Sleet. The report described the same plain-crypto-js dependency chain and cross-platform second-stage payload delivery.
Google Threat Intelligence Group attributed the supply-chain compromise to UNC1069, a financially motivated North Korea-linked actor, citing infrastructure overlap and use of WAVESHAPER.V2. Several reports explicitly anchor this attribution to April 1, 2026.
CrowdStrike assessed with moderate confidence that STARDUST CHOLLIMA was behind the Axios compromise, citing malware and infrastructure overlaps and describing the payloads as updated ZshBucket variants. The report explicitly dates the malicious publishing to March 31, 2026.
The npm package page states plain-crypto-js was removed because it contained malicious code and that npm published a placeholder version, 0.0.1-security.0, to prevent future abuse of the package name.
The malicious Axios versions were removed from npm after a short exposure window of roughly three hours. Finnish Traficom alerts explicitly state the packages were removed at 03:29 UTC on 2026-03-31.
Expel said it detected related activity at a customer around 2026-03-31T00:50:00 UTC and then issued customer communications and an emerging threat hunt. This is an explicit observation of real-world downstream impact during the compromise window.
Elastic Security Labs said it filed a GitHub Security Advisory to the axios repository to coordinate disclosure with maintainers and npm. The filing time was given as 01:50 AM UTC on March 31, 2026.
Socket reported its automated malware detection flagged plain-crypto-js shortly after publication, within minutes of the malicious release sequence. Multiple reports place this detection on March 31, 2026.
The injected plain-crypto-js dependency used a postinstall script and obfuscated dropper to fetch platform-specific payloads from sfrclak[.]com:8000 for Windows, macOS, and Linux. Reports said the malware supported reconnaissance, command execution, persistence on Windows, and anti-forensic cleanup that restored benign-looking package metadata.
Attackers used the compromised maintainer account to publish axios versions 1.14.1 and 0.30.4 directly to npm, bypassing the project's normal GitHub Actions OIDC workflow. The releases added plain-crypto-js@4.2.1 as a dependency, turning Axios installs into a malware delivery path.
Researchers reported the attacker pre-positioned the package name plain-crypto-js by publishing a clean 4.2.0 release before weaponizing it, apparently to make the dependency look legitimate.
The attacker published plain-crypto-js@4.2.1 as the malicious dependency later pulled by compromised Axios releases. Socket said this package was published on 2026-03-30.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
50 references tracked. Mallory keeps watching after this page renders.
medium.com
Open sourcecsirt.sk
Open sourcecybersecuritynews.com
Open sourceblog.knowbe4.com
Open sourcezscaler.com
Open sourcesocket.dev
Open sourceblog.talosintelligence.com
Open sourceveracode.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.