Axios compromised: hijacked maintainer account pushes malicious npm versions
Blog post from Endor Labs
In a significant security breach on March 31, 2026, an attacker compromised the npm credentials of the lead maintainer of axios, a major JavaScript package with over 400 million monthly downloads, to publish two malicious versions: [email protected] and [email protected]. Instead of altering the axios code, the attacker injected a deceptive dependency, plain-crypto-js, which was a typosquat of the legitimate crypto-js library, aimed at silently installing malware when axios was added to projects. This malware contacted a server controlled by the attacker, downloaded remote access trojans tailored for different operating systems, and erased its tracks to evade detection, granting the attacker full control over affected machines. The malicious versions were removed by npm within approximately three hours, and the plain-crypto-js package was replaced with a security placeholder. The incident highlighted the need for stringent security measures, including pinning dependencies, disabling lifecycle scripts in CI/CD environments, and adopting a minimum release age policy to protect against such attacks.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 2 | 1,488 | 268 | 99 | +7% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.