Hacker hijacks Axios open-source project, used by millions, to push malware
image via TechCrunch
March 31, 2026, 4:01 PM
- •A hacker inserted malicious code into the Axios library.
- •The malicious code was designed to deliver a remote access trojan (RAT).
- •The attack targeted Windows, macOS, and Linux users.
- •The incident highlights the threat of supply chain attacks.
A hacker compromised a primary developer's account and injected malicious code into the popular JavaScript library Axios, which is used by millions of developers to connect their software to the internet. The compromised code, hosted on npm, delivered a remote access trojan (RAT) designed to give hackers full remote control of a victim's computer. The attack, which targeted Windows, macOS, and Linux users, was quickly identified and stopped within hours, but the incident highlights the ongoing threat of supply chain attacks. Anyone who downloaded the malicious code should assume their system is compromised.
Entities Mentioned
Lorenzo Franceschi-Bicchierai
Topics Covered
Securityaxioscybercrimecybersecurityhackershackinginfosecmalwaresupply chain attack
Comments (0)
No comments yet.