1
Published signals
currently linked to this company
Company intelligence
axios.com
This company page brings together public reporting currently associated with Axios. It reflects signals published by Shadow Tier and should not be read as a complete incident history.
Company links
1
currently linked to this company
1
recent published signals
1
recent published signals
0
confidence classifications
July 25, 2026
most recent published signal
Explore related intelligence
Based on all published signals currently linked to Axios. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.
Company signals
On July 23, 2026, the Axios npm package, a widely used JavaScript HTTP client, was compromised in a sophisticated supply chain attack. The attackers hijacked a maintainer account and injected a malicious dependency, `plain-crypto-js`, into versions `axios@1.14.1` and `axios@0.30.4`. This malicious dependency was designed to download multi-stage payloads, including a remote access trojan, onto developer machines and CI/CD pipelines globally. The compromise was detected and the malicious packages were removed from npm within approximately three hours. The attack was characterized by its operational sophistication, bypassing standard security controls like MFA through a targeted social engineering campaign against the maintainer. The malicious code was capable of breaching major operating systems including Windows, macOS, and Linux. CISA issued an alert providing guidance for detection and remediation, urging organizations to monitor code repositories, CI/CD pipelines, and developer machines, and to rotate credentials that may have been exposed. Google Threat Intelligence Group publicly attributed the compromise to UNC1069, a North Korea-nexus, financially motivated threat actor. The incident highlights the significant risks associated with software supply chain attacks and the importance of robust security measures for open-source dependencies.
FAQ
It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Axios.
No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.
The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.