Attackers hijacked an Axios maintainer's npm account and published malicious package versions axios@1.14.1 and axios@0.30.4, turning one of npm's most widely used JavaScript libraries into a supply-chain malware delivery channel. The poisoned releases, tracked as MAL-2026-2306 and GHSA-2x9r-6wxq-hrr7, reportedly introduced a hidden dependency, plain-crypto-js@4.2.1, whose postinstall behavior fetched a cross-platform remote access trojan for macOS, Windows, and Linux. The attacker is reported to have used a long-lived classic npm token, changed the maintainer account email, and bypassed the project's normal trusted publishing workflow by releasing directly through the npm CLI.
The malicious packages were available for roughly three hours before removal, but defenders were urged to treat any host or CI runner that installed them as fully compromised. Reported indicators included outbound connections to sfrclak[.]com:8000 and artifacts such as /Library/Caches/com.apple.act.mond on macOS, %PROGRAMDATA%\wt.exe on Windows, and /tmp/ld.py on Linux, with associated infrastructure including 142.11.206.73. Security guidance called for downgrading to axios@1.14.0 or 0.30.3, blocking the command-and-control domain, rebuilding affected systems from known-good images, rotating exposed credentials, and adopting controls such as delayed installation of newly published npm packages and disabling install scripts in CI/CD where feasible.

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
AWS Security Blog later referenced the March 2026 Axios compromise as a supply-chain incident that a one-day dependency cooldown would have blocked during its short exposure window.
The poisoned Axios releases were taken down from npm roughly two to three hours after publication, limiting but not eliminating exposure for users who installed them.
After compromising an Axios maintainer's npm credentials, attackers published malicious versions axios@1.14.1 and axios@0.30.4 that added plain-crypto-js and installed a cross-platform RAT on macOS, Windows, and Linux systems.
The attacker published plain-crypto-js@4.2.1 at 23:59 UTC, embedding a postinstall hook used to fetch platform-specific malware.
A separate npm account, nrwise, published a clean decoy package plain-crypto-js@4.2.0 to establish publishing history before the Axios compromise.
Security writeups documented the compromise, identified IOCs including sfrclak[.]com and 142.11.206.73, and advised affected organizations to downgrade Axios, inspect hosts and CI runners, rebuild compromised systems, and rotate credentials.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 23 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
12 references tracked. Mallory keeps watching after this page renders.
trendaisecurity.com
Open sourceaws.amazon.com
Open sourcesemgrep.dev
Open sourcelegitsecurity.com
Open sourcelabs.beazley.security
Open sourcestepsecurity.io
Open sourceaikido.dev
Open sourcenpmjs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.