Story perspectives
Supply Chain Attack Compromises Axios Package — Users Urged to Downgrade
3/31/2026
1 of 1
Story summary
- A supply chain attack compromised the Axios JavaScript package, affecting versions 1.14.1 and 0.30.4.
- Attackers used the compromised npm account of Jason Saayman, Axios maintainer, to publish the malicious dependency plain-crypto-js 4.2.1.
- Plain-crypto-js functions as a remote access Trojan across macOS, Windows, and Linux.
- Users should downgrade to 1.14.0 or 0.30.3 and check for signs of compromise.
