Axios npm Package Hacked: Cross-Platform Malware Alert!

Date:

Malware Attack Targets Axios npm Package, Affecting Millions

In a significant cybersecurity incident, hackers compromised the npm account of the popular Axios package, a JavaScript HTTP client with over 100 million weekly downloads. The attackers published two malicious versions of Axios, injecting remote access trojans (RATs) that target Linux, Windows, and macOS systems.

The attack occurred during a three-hour window, and with Axios’s widespread use, the number of affected projects is likely substantial. The malicious updates executed scripts that allowed the attackers to maintain control over infected systems, posing serious risks to users.

To protect against this threat, Axios users should revert to the last known safe versions, axios@1.14.0 and axios@0.30.3. Additionally, users are advised to rotate credentials and rebuild affected environments from a secure state.

Risk Level: High. This incident highlights the vulnerabilities in software supply chains, emphasizing the need for vigilance in software updates.

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

Critical PHP Object Injection Vulnerability Found in GiveWP Plugin

A recently discovered vulnerability in the GiveWP plugin poses...

AI Advances Strengthen Cybersecurity: Wordfence Unveils Critical Vulnerability Discovery

Wordfence has revealed significant advancements in its incorporation of...

Critical Unauthenticated Account Takeover Vulnerability Found in TranslatePress Plugin

On August 11, 2026, a significant security vulnerability was...

Hackers Target WordPress Sites in miniOrange Authentication Bypass Attacks

In recent weeks, hackers have escalated their attacks on...