Attackers compromised an Axios maintainer’s npm account and published malicious axios versions 1.14.1 and 0.30.4. Rather than alter Axios directly, they added the plain-crypto-js dependency, whose postinstall hook deployed cross-platform malware on affected systems. The maintainer account’s associated email address was changed to a ProtonMail address during the takeover.
Elastic Security Labs detected the releases with a proof-of-concept package-monitoring system that analyzed package diffs, and telemetry showed organizations had installed the compromised versions. Axios maintainers subsequently removed the malicious releases. Organizations should identify and remove the affected versions, investigate installations for plain-crypto-js postinstall execution, rotate npm credentials where compromise is suspected, and delay adoption of newly released packages while monitoring dependency changes.

Trace attribution and downstream blast radius.
10 events from the most recent confirmed update back to the earliest known activity.
TeamPCP allegedly used PyPI publishing credentials stolen through the Trivy compromise to publish malicious LiteLLM versions targeting SSH keys, cloud credentials, API keys, and wallet data.
TeamPCP reportedly compromised the aquasecurity/trivy-action GitHub Action and injected a credential stealer that harvested CI/CD secrets.
Elastic Security Labs reported significant code and behavioral overlap between the macOS RAT delivered through the malicious Axios dependency and WAVESHAPER, a C++ backdoor Mandiant associates with the DPRK-linked UNC1069 cluster.
Elastic open-sourced supply-chain-monitor, a proof-of-concept tool that monitors selected npm and PyPI releases, generates static package-diff reports without executing package code, and uses LLM-based classification.
TeamPCP reportedly compromised the telnyx PyPI package by adding malicious code to _client.py, including WAV-file steganography, Base64 obfuscation, a Windows persistence component disguised as msbuild.exe, and exfiltration to a hardcoded command-and-control server.
Elastic Security Labs published technical analysis of the reported Axios attack chain, malware, and command-and-control protocol, along with detection and hunting guidance for Linux, Windows, and macOS.
After notification, Axios maintainers reportedly removed the malicious package versions from npm.
Elastic's proof-of-concept supply-chain-monitor generated a Slack alert identifying npm package axios version 0.30.4 as malicious. Elastic Defend also generated alerts on a host that installed the malicious package.
The compromised Axios releases added the plain-crypto-js dependency rather than modifying Axios source code directly. Its postinstall hook reportedly deployed cross-platform malware, and Elastic telemetry showed affected organizations had installed the package.
Attackers reportedly took over an Axios maintainer's npm account, changed its associated email address to an attacker-controlled ProtonMail address, and published malicious Axios releases 1.14.1 and 0.30.4.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.