Corpus graph previewActor to Incident
Supply Chain GraphPan, zoom, and select actor, campaign, and incident tiers.

Supply Chain graph is loading. Keyboard controls become available after graph initialization.

Supply Chain Incident

Focused Graph View

The persistent graph is framed to this incident while the canonical page heading and details continue below.

270 nodes467 edgesCold links hydrate here

Supply Chain Incident

Axios npm maintainer account compromise

A compromised Axios maintainer account published malicious npm releases that added plain-crypto-js as an install-time dependency delivering a cross-platform remote access trojan.

ConfidenceHigh
Evidence LevelPrimary
Attack StageAccount Compromise
Source Artifact DivergenceYes
Attribution ConfidenceDisputed

Evidence-Gated Propagation

Propagation Timeline

  1. Releaseplain-crypto-js@4.2.1pkg:npm/plain-crypto-js@4.2.1
    Releaseaxios@0.30.4pkg:npm/axios@0.30.4

    The same malicious plain-crypto-js dependency was introduced into both compromised Axios release lines.

  2. Releaseplain-crypto-js@4.2.1pkg:npm/plain-crypto-js@4.2.1
    Releaseaxios@1.14.1pkg:npm/axios@1.14.1

    The Axios postmortem and Google analysis describe malicious Axios releases depending on plain-crypto-js 4.2.1 as the install-time payload carrier.

Affected Packages

Affected Releases

  • axios@0.30.4pkg:npm/axios@0.30.4 · published 2026-03-31Release
  • axios@1.14.1pkg:npm/axios@1.14.1 · published 2026-03-31Release
  • plain-crypto-js@4.2.1pkg:npm/plain-crypto-js@4.2.1 · published 2026-03-31Release

Repositories

Organizations

Maintainers

Threat Actors

Campaigns

No structured records.

Build Systems

No structured records.

Distribution Channels

  • npm registry

Compromised Accounts

  • axios maintainer npm account

Connected Entities

Attribution Evidence

References