On March 30–31, 2026, the JavaScript ecosystem experienced a significant supply chain security incident involving one of the most widely used libraries in modern development: Axios.
While Daployi was not affected by this attack, the event highlights important lessons for any team deploying software across distributed systems, edge environments, or CI/CD pipelines.
This post breaks down what happened, how the attack worked, and how you can verify whether your systems were exposed.
What Happened
An attacker gained access to the npm account of an Axios maintainer and published malicious versions of the package:
-
axios @ 1.14.1
-
axios @ 0.30.4
These versions were available for a short period (~2–3 hours). During that window, any system installing Axios without strict version control may have executed malicious code.
Important Clarification
This was not a vulnerability in Axios itself.
This was a software supply chain attack, where the npm distribution channel was compromised.
How the Attack Worked
- Maintainer Account Compromise
The attacker accessed a trusted npm account. - Malicious Dependency Injection
A hidden dependency (plain-crypto-js) was added. - Install-Time Execution
A postinstall script executed automatically during npm install. - Payload Deployment
A cross-platform RAT (Remote Access Trojan) was installed. - Stealth Techniques
The malware removed traces and attempted to appear clean.
Why This Matters
Axios is deeply embedded across:
- Frontend apps
- Backend services
- CI/CD pipelines
- Internal tooling
This means even a short-lived attack window can impact:
- Developer machines
- Build infrastructure
- Production systems
Was Daployi Affected?
No.
We do not use Axios in our platform, which meant this specific compromise did not impact our systems.
More importantly, our deployment architecture limits exposure to install-time dependency risks by separating build and runtime environments and enforcing controlled deployment workflows.
🔍 Am I Affected?
🚨 Known malicious versions
- axios @ 1.14.1
- axios @ 0.30.4
✅ Safe versions
- axios @ 1.14.0
- axios @ 0.30.3
Quick Check
Run:
npm list axios
npm list -g axios
If either command shows a malicious version, assume compromise.
Manual Detection (Advanced)
1. Scan Your System for Axios Versions
Mac / Linux
find / -path “*/node_modules/axios/package.json” 2>/dev/null | while read f; do
version=$(grep ‘”version”‘ “$f” | head -1)
echo “$f -> $version”
done
Windows (PowerShell)
Get-ChildItem -Path C: -Recurse -Filter “package.json” -ErrorAction SilentlyContinue |
Where-Object { $_.DirectoryName -like “*node_modulesaxios” } |
ForEach-Object {
$version = (Get-Content $_.FullName | Select-String ‘”version”‘).Line
Write-Output “$($_.FullName) -> $version”
}
👉 If any result shows 1.14.1 or 0.30.4, investigate immediately.
2. Check Lockfile History
git log -p — package-lock.json | grep “plain-crypto-js”
⚠️ Red flag:
- plain-crypto-js appearing in your dependency tree
Legitimate Axios only includes:
- follow-redirects
- form-data
- proxy-from-env
3. Check for RAT Artifacts
macOS
ls -la /Library/Caches/com.apple.act.mond 2>/dev/null
Linux
ls -la /tmp/ld.py 2>/dev/null
Windows (PowerShell)
Test-Path “$env:PROGRAMDATAwt.exe”
4. Check for Suspicious Network Activity
netstat -an | grep “142.11.206.73”
If you see connections to this IP, treat the system as compromised.
If You Were Affected
If any of the checks above indicate exposure:
- Rotate all credentials (API keys, tokens, SSH keys)
- Rebuild affected systems or containers
- Audit logs for unusual activity
- Review CI/CD pipelines for unauthorized changes
Key Takeaways
- Supply chain attacks are increasing
- Install-time scripts are high risk
- Version pinning is essential
- CI/CD systems are prime targets
Final Thoughts
This incident is a reminder that modern software delivery depends on trust across a complex ecosystem.
At Daployi, we believe that controlled deployment, visibility, and deliberate execution are critical to reducing this risk—especially in distributed and edge environments.
Now is a good time to review how dependencies are introduced and executed across your infrastructure.

