The post Axios NPM Package Compromised in Supply Chain Attack appeared on BitcoinEthereumNews.com. Update March 31, 2026, 1:28 pm UTC: This article has been updatedThe post Axios NPM Package Compromised in Supply Chain Attack appeared on BitcoinEthereumNews.com. Update March 31, 2026, 1:28 pm UTC: This article has been updated

Axios NPM Package Compromised in Supply Chain Attack

2026/04/01 10:18
Okuma süresi: 3 dk
Bu içerikle ilgili geri bildirim veya endişeleriniz için lütfen crypto.news@mexc.com üzerinden bizimle iletişime geçin.

Update March 31, 2026, 1:28 pm UTC: This article has been updated to add comments from Abdelfattah Ibrahim, senior offensive security engineer at Hacken.

Two malicious Axios npm releases have prompted warnings for developers to rotate credentials and treat affected systems as compromised after a supply chain attack poisoned the popular JavaScript HTTP client library.

The compromise was first reported by cybersecurity company Socket, which said [email protected] and [email protected] were modified to pull in [email protected], a malicious dependency that ran automatically during installation before the releases were removed from npm.

According to security company OX Security, the altered code can give attackers remote access to infected devices, allowing them to steal sensitive data such as login credentials, API keys and crypto wallet information.

The incident shows how a single compromised open-source component can potentially ripple across thousands of applications that rely on it, exposing not just developers but also platforms and users connected to the system. 

Security companies urge key rotation, system audits

OX Security warned developers who installed [email protected] or [email protected] to treat their systems as fully compromised and immediately rotate credentials, including API keys and session tokens.

Socket said the compromised Axios releases were modified to include a dependency on [email protected], a package published shortly before the incident and later identified as malicious.

Related: Trust Wallet browser extension knocked offline by Chrome Store ‘bug,’ CEO says

The company said the dependency was configured to run automatically during installation through a post-install script, allowing attackers to execute code on target systems without additional user interaction.

Socket advised developers to review their projects and dependency files for the affected Axios versions and the associated [email protected] package, and to remove or roll back any compromised versions immediately.

Abdelfattah Ibrahim, senior offensive security engineer at Hacken, told Cointelegraph that the compromise could have serious implications for crypto-related applications that rely on Axios for backend operations.

“That’s bad news for dapps and apps that deal with cryptocurrency because Axios plays a huge role in API calls,” he said, noting that affected systems could include exchange integrations, wallet balance checks and transaction broadcasts.

Ibrahim said the malware deployed in the attack functions as a full remote access trojan, allowing attackers to interact directly with compromised systems. He added that the incident highlights a broader weakness in how supply chain risks are handled.

Earlier crypto incidents highlight supply chain risks

Earlier crypto incidents have shown how supply chain breaches can escalate from stolen developer information to user-facing wallet losses.

On Jan. 3, onchain investigator ZachXBT reported that “hundreds” of wallets across Ethereum Virtual Machine-compatible networks were drained in a broad attack that siphoned small amounts from each victim. 

Cybersecurity researcher Vladimir S. said the incident was potentially linked to a December breach affecting Trust Wallet, which resulted in roughly $7 million in losses across over 2,500 wallets. 

Trust Wallet later said the breach may have originated from a supply chain compromise involving npm packages used in its development workflow.

Magazine: Nobody knows if quantum secure cryptography will even work

Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently. Read our Editorial Policy https://cointelegraph.com/editorial-policy

Source: https://cointelegraph.com/news/axios-npm-supply-chain-attack-malicious-dependency?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

Piyasa Fırsatı
4 Logosu
4 Fiyatı(4)
$0.011914
$0.011914$0.011914
-1.40%
USD
4 (4) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen crypto.news@mexc.com ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Trade GOLD, Share 1,000,000 USDT

Trade GOLD, Share 1,000,000 USDTTrade GOLD, Share 1,000,000 USDT

0 fees, up to 1,000x leverage, deep liquidity