Drooid Logo
Back to today’s briefing

Story perspectives

Supply Chain Attack Compromises Axios Package — Users Urged to Downgrade

3/31/2026

38 8 Full Breakdown

1 of 1

Story summary
  • A supply chain attack compromised the Axios JavaScript package, affecting versions 1.14.1 and 0.30.4.
  • Attackers used the compromised npm account of Jason Saayman, Axios maintainer, to publish the malicious dependency plain-crypto-js 4.2.1.
  • Plain-crypto-js functions as a remote access Trojan across macOS, Windows, and Linux.
  • Users should downgrade to 1.14.0 or 0.30.3 and check for signs of compromise.