Skip to main content
Back to overview
Medium

Axios npm package compromised in supply chain attack on July 23, 2026

On July 23, 2026, the Axios npm package, a widely used JavaScript HTTP client, was compromised in a sophisticated supply chain attack.

Key points

  • Axios npm package compromised on July 23, 2026.
  • Malicious dependency `plain-crypto-js` injected into `axios@1.14.1` and `axios@0.30.4`.
  • Attack involved a remote access trojan and targeted developer machines and CI/CD pipelines.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Phishing Social Engineering

Threat source not confirmed

03

Potential impact

Potential fraud or account takeover risk

Confidentiality

Published
Jul 23, 2026
Updated
Jul 25, 2026
Confidence
Medium
Evidence
5 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch phishing, executive impersonation and account-takeover exposure.

Business impact

Potential fraud or account takeover risk
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

AxiosData DisclosureAxiosOn JulyJavaScript HTTPMFAWindowsLinux. CISAGoogle Threat Intelligence GroupUNC1069

Quick context

Questions about this signal

What happened in this signal?

On July 23, 2026, the Axios npm package, a widely used JavaScript HTTP client, was compromised in a sophisticated supply chain attack. The attackers hijacked a maintainer account and injected a malicious dependency, `plain-crypto-js`, into versions `axios@1.14.1` and `axios@0.30.4`. This malicious dependency was designed to download multi-stage payloads, including a remote access trojan, onto developer machines and CI/CD pipelines globally. The compromise was detected and the malicious packages were removed from npm within approximately three hours. The attack was characterized by its operational sophistication, bypassing standard security controls like MFA through a targeted social engineering campaign against the maintainer. The malicious code was capable of breaching major operating systems including Windows, macOS, and Linux. CISA issued an alert providing guidance for detection and remediation, urging organizations to monitor code repositories, CI/CD pipelines, and developer machines, and to rotate credentials that may have been exposed. Google Threat Intelligence Group publicly attributed the compromise to UNC1069, a North Korea-nexus, financially motivated threat actor. The incident highlights the significant risks associated with software supply chain attacks and the importance of robust security measures for open-source dependencies.

When was this signal reported?

Shadow Tier lists Jul 23, 2026 as the signal date.

Which organization is connected to this signal?

Axios is the organization connected to this public signal.

Explore Axios
Which attack pattern is relevant?

This signal is connected to phishing and social-engineering intelligence based on its reported incident context.

Explore phishing and social-engineering intelligence