Supply Chain Incident
Axios npm maintainer account compromise
A compromised Axios maintainer account published malicious npm releases that added plain-crypto-js as an install-time dependency delivering a cross-platform remote access trojan.
Evidence-Gated Propagation
Propagation Timeline
- Releaseplain-crypto-js@4.2.1
pkg:npm/plain-crypto-js@4.2.1CausalReleaseaxios@0.30.4pkg:npm/axios@0.30.4The same malicious plain-crypto-js dependency was introduced into both compromised Axios release lines.
- Releaseplain-crypto-js@4.2.1
pkg:npm/plain-crypto-js@4.2.1CausalReleaseaxios@1.14.1pkg:npm/axios@1.14.1The Axios postmortem and Google analysis describe malicious Axios releases depending on plain-crypto-js 4.2.1 as the install-time payload carrier.
Affected Packages
Affected Releases
- axios@0.30.4pkg:npm/axios@0.30.4 · published 2026-03-31Release
- axios@1.14.1pkg:npm/axios@1.14.1 · published 2026-03-31Release
- plain-crypto-js@4.2.1pkg:npm/plain-crypto-js@4.2.1 · published 2026-03-31Release
Repositories
Organizations
Maintainers
Threat Actors
- TeamPCP
- UNC1069
Campaigns
No structured records.
Build Systems
No structured records.
Distribution Channels
- npm registry
Compromised Accounts
- axios maintainer npm account
Connected Entities
- axiosPackage
- AxiosOrganization
- axios maintainer npm accountCompromised Account
- axios@0.30.4Release
- axios@1.14.1Release
- axios/axiosRepository
- Jason SaaymanMaintainer
- npm registryDistribution Channel
- plain-crypto-jsPackage
- plain-crypto-js@4.2.1Release
- TeamPCPThreat Actor
- UNC1069Threat Actor
Attribution Evidence
Google Threat Intelligence Group attributes the Axios npm compromise to a North Korea-nexus actor tracked as UNC1069.
Trend Micro covered the Axios compromise in the same active supply-chain period, while Datadog explicitly reports the TTPs do not match TeamPCP; this edge remains disputed rather than asserted.
References
- Post Mortem: axios npm supply chain compromise #10636Axios Maintainers · 2026-03-31
- North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM PackageGoogle Threat Intelligence Group · 2026-04-02
- Supply Chain Compromise Impacts Axios Node Package ManagerCybersecurity and Infrastructure Security Agency · 2026-04-20
- Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly DownloadsTrend Micro · 2026-03-31
- Compromised axios npm package delivers cross-platform RATDatadog Security Labs · 2026-04-01