The Axios npm Supply Chain Attack: What Happened and Why It Matters

Axios Attack Impact Discussion Daployi March 2026

On March 30–31, 2026, the JavaScript ecosystem experienced a significant supply chain security incident involving one of the most widely used libraries in modern development: Axios.

While Daployi was not affected by this attack, the event highlights important lessons for any team deploying software across distributed systems, edge environments, or CI/CD pipelines.

This post breaks down what happened, how the attack worked, and how you can verify whether your systems were exposed.

 

What Happened

An attacker gained access to the npm account of an Axios maintainer and published malicious versions of the package:

  • axios @ 1.14.1

  • axios @ 0.30.4

These versions were available for a short period (~2–3 hours). During that window, any system installing Axios without strict version control may have executed malicious code.

 

Important Clarification

This was not a vulnerability in Axios itself.

This was a software supply chain attack, where the npm distribution channel was compromised.

 

How the Attack Worked

  1. Maintainer Account Compromise
    The attacker accessed a trusted npm account.
  2. Malicious Dependency Injection
    A hidden dependency (plain-crypto-js) was added.
  3. Install-Time Execution
    A postinstall script executed automatically during npm install.
  4. Payload Deployment
    A cross-platform RAT (Remote Access Trojan) was installed.
  5. Stealth Techniques
    The malware removed traces and attempted to appear clean.

 

Why This Matters

Axios is deeply embedded across:

  • Frontend apps
  • Backend services
  • CI/CD pipelines
  • Internal tooling

This means even a short-lived attack window can impact:

  • Developer machines
  • Build infrastructure
  • Production systems

 

Was Daployi Affected?

No.

We do not use Axios in our platform, which meant this specific compromise did not impact our systems.

More importantly, our deployment architecture limits exposure to install-time dependency risks by separating build and runtime environments and enforcing controlled deployment workflows.

 

🔍 Am I Affected?

🚨 Known malicious versions

  • axios @ 1.14.1
  • axios @ 0.30.4

✅ Safe versions

  • axios @ 1.14.0
  • axios @ 0.30.3

Quick Check

Run:

npm list axios
npm list -g axios

If either command shows a malicious version, assume compromise.

 

Manual Detection (Advanced)

1. Scan Your System for Axios Versions

Mac / Linux

find / -path “*/node_modules/axios/package.json” 2>/dev/null | while read f; do

  version=$(grep ‘”version”‘ “$f” | head -1)

  echo “$f -> $version”

done

Windows (PowerShell)

Get-ChildItem -Path C: -Recurse -Filter “package.json” -ErrorAction SilentlyContinue |

  Where-Object { $_.DirectoryName -like “*node_modulesaxios” } |

  ForEach-Object {

    $version = (Get-Content $_.FullName | Select-String ‘”version”‘).Line

    Write-Output “$($_.FullName) -> $version”

  }

👉 If any result shows 1.14.1 or 0.30.4, investigate immediately.

2. Check Lockfile History

git log -p — package-lock.json | grep “plain-crypto-js”

⚠️ Red flag:

  • plain-crypto-js appearing in your dependency tree

Legitimate Axios only includes:

  • follow-redirects
  • form-data
  • proxy-from-env

3. Check for RAT Artifacts

macOS

ls -la /Library/Caches/com.apple.act.mond 2>/dev/null

Linux

ls -la /tmp/ld.py 2>/dev/null

Windows (PowerShell)

Test-Path “$env:PROGRAMDATAwt.exe”

4. Check for Suspicious Network Activity

netstat -an | grep “142.11.206.73”

If you see connections to this IP, treat the system as compromised.

 

If You Were Affected

If any of the checks above indicate exposure:

  • Rotate all credentials (API keys, tokens, SSH keys)
  • Rebuild affected systems or containers
  • Audit logs for unusual activity
  • Review CI/CD pipelines for unauthorized changes

 

Key Takeaways

  • Supply chain attacks are increasing
  • Install-time scripts are high risk
  • Version pinning is essential
  • CI/CD systems are prime targets

 

Final Thoughts

This incident is a reminder that modern software delivery depends on trust across a complex ecosystem.

At Daployi, we believe that controlled deployment, visibility, and deliberate execution are critical to reducing this risk—especially in distributed and edge environments.

Now is a good time to review how dependencies are introduced and executed across your infrastructure.