Axios npm Package Compromised in Supply Chain Attack

📰 InfoQ AI/ML

On March 31, 2026, two versions of the Axios library were compromised and found to contain a Remote Access Trojan. The malicious packages were published through a hijacked maintainer account. The Axios team is investigating how the breach occurred and has deprecated the affected versions. Security experts emphasize the need for better dependency management. By Daniel

Published 2 Apr 2026
Read full article → ← Back to News