Attackers compromised an Axios maintainer's npm credentials and published two malicious package versions, axios@1.14.1 and axios@0.30.4, to the npm registry. The trojanized releases targeted one of the JavaScript ecosystem's most widely used libraries and were reported to fetch and install a cross-platform remote access trojan affecting macOS, Windows, and Linux systems. Security reporting said the malicious packages were available for roughly three hours before removal, creating a high-impact software supply chain incident for organizations that automatically pulled newly released dependencies.
Defenders were urged to identify any installations of the affected Axios versions, treat exposed hosts as fully compromised, and rebuild impacted systems from known-good images rather than relying only on package rollback. Additional containment guidance included blocking the command-and-control domain sfrclak[.]com on port 8000, pinning Axios to known-safe versions, delaying adoption of freshly published npm releases, and disabling install scripts in CI/CD pipelines where feasible to reduce exposure to similar dependency attacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Security researchers released public analysis of the Axios supply chain incident, including indicators of compromise, affected versions, command-and-control infrastructure such as sfrclak[.]com on port 8000, and recommended containment steps. Guidance included pinning to safe versions, rebuilding compromised systems, and limiting install scripts in CI/CD where possible.
The malicious Axios versions were taken down from the npm registry within about three hours of publication. Organizations that installed them were advised to treat affected machines as fully compromised.
Attackers compromised an Axios developer's npm credentials and published malicious packages axios@1.14.1 and axios@0.30.4 to the npm registry. The trojanized releases delivered a cross-platform remote access trojan affecting macOS, Windows, and Linux systems.
5 references tracked. Mallory keeps watching after this page renders.
semgrep.dev
Open sourcesans.org
Open sourcelinkedin.com
Open sourcelabs.beazley.security
Open sourcestepsecurity.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.