MEDIUMMalware
Global
Hackers compromise Axios npm package to drop cross-platform malware
Tuesday, March 31, 2026 at 01:53 PM UTC·Source: BleepingComputer
Updated: Wednesday, April 1, 2026 at 07:13 PM UTC
Executive Summary
Hackers hijacked the npm account of the Axios package, a JavaScript HTTP client with 100M+ weekly downloads, to deliver remote access trojans to Linux, Windows, and macOS systems. [...]
Analysis
Hackers hijacked the npm account of the Axios package, a JavaScript HTTP client with 100M+ weekly downloads, to deliver remote access trojans to Linux, Windows, and macOS systems. [...]