{"id":42604,"date":"2026-03-31T04:52:06","date_gmt":"2026-03-31T04:52:06","guid":{"rendered":"https:\/\/financialrush.com\/?p=42604"},"modified":"2026-03-31T04:52:06","modified_gmt":"2026-03-31T04:52:06","slug":"expert-warns-of-critical-ongoing-supply-chain-attack-on-axios","status":"publish","type":"post","link":"https:\/\/financialrush.com\/?p=42604","title":{"rendered":"Expert Warns of Critical, Ongoing Supply Chain Attack on Axios"},"content":{"rendered":"<p> \n<br \/><\/p>\n<div>\n<p>&#13;<br \/>\n\t\t\t\t\t\t\t\t\tOne of NPM&#8217;s most depended-on packages is under an ongoing supply chain attack. \t\t\t\t\t\t\t\t<\/p>\n<\/p><\/div>\n<div>\n<p>According to Feross Aboukhadijeh, co-founder of security-oriented firm Socket Security, there is an active supply chain on Axios, which is one of npm\u2019s most depended-on packages.<\/p>\n<p>NPM stands for Node Package Manager and is basically the world\u2019s largest software registry, hosting more than two million packages of open-source JavaScript code. An argument can be made that it\u2019s the backbone of modern Web3 development.<\/p>\n<p>According to Feross, the latest axios@1.14.1 is currently pulling in plain-crypto-just@4.2.1, which is a package that did not exist before today, suggesting that it\u2019s a live compromise.<\/p>\n<blockquote>\n<p>This is textbook supply chain installer malware. Axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analyiss confirms this is malware. Plain-crypto-js is an obfuscated dropper\/loadre.\u201d<\/p>\n<\/blockquote>\n<p>The malicious software can perform a range of actions, including deleting and renaming artifacts post-execution to destroy forensic evidence, staging and copying payload files to the OS temp and Windows ProgramData directories, executing decoded shell commands, and more.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">\ud83d\udea8 CRITICAL: Active supply chain attack on axios \u2014 one of npm\u2019s most depended-on packages.<\/p>\n<p>The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise.<\/p>\n<p>This is textbook supply chain installer malware. axios\u2026<\/p>\n<p>\u2014 Feross (@feross) <a href=\"https:\/\/twitter.com\/feross\/status\/2038807290422370479?ref_src=twsrc%5Etfw\" target=\"_blank\">March 31, 2026<\/a><\/p>\n<\/blockquote>\n<p>The expert recommends that developers who use axios immediately pin their versions and audit their lockfiles, while refraining from any updates for the time being.<\/p>\n<div class=\"code-block code-block-12\" style=\"margin: 8px 0; clear: both;\">\n<div><center><span style=\"font-size:11px; color: gray;\">SPECIAL OFFER (Exclusive)<\/span><\/center><br \/>\n<b>Binance Free $600 (CryptoPotato Exclusive): <a href=\"https:\/\/cryptopotato.com\/binance600f\/\" rel=\"nofollow\">Use this link<\/a> to register a new account and receive $600 exclusive welcome offer on Binance<\/b> (<a href=\"https:\/\/cryptopotato.com\/binance600d\/\">full details<\/a>).<\/p>\n<p><b>LIMITED OFFER for CryptoPotato readers at Bybit: <a href=\"https:\/\/cryptopotato.com\/pl\/bybit24\/\" rel=\"nofollow\">Use this link<\/a> to register and open a $500 FREE position on any coin!<\/b><\/p>\n<\/div>\n<\/div>\n<p><!-- CONTENT END 1 --><\/p><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/>\n<br \/><a href=\"https:\/\/cryptopotato.com\/expert-warns-of-critical-ongoing-supply-chain-attack-on-axios\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"&#13; One of NPM&#8217;s most depended-on packages is under an ongoing supply chain attack. According to Feross Aboukhadijeh,&hellip;\n","protected":false},"author":2,"featured_media":36302,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13],"tags":[],"class_list":["post-42604","post","type-post","status-publish","format-standard","has-post-thumbnail","category-crypto","cs-entry","cs-video-wrap"],"_links":{"self":[{"href":"https:\/\/financialrush.com\/index.php?rest_route=\/wp\/v2\/posts\/42604","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/financialrush.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/financialrush.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/financialrush.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/financialrush.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=42604"}],"version-history":[{"count":0,"href":"https:\/\/financialrush.com\/index.php?rest_route=\/wp\/v2\/posts\/42604\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/financialrush.com\/index.php?rest_route=\/wp\/v2\/media\/36302"}],"wp:attachment":[{"href":"https:\/\/financialrush.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=42604"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/financialrush.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=42604"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/financialrush.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=42604"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}