Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Axios Front-End Library npm Supply Chain Poisoning Alert

0
Medium
Published: Wed Apr 01 2026 (04/01/2026, 13:16:21 UTC)
Source: AlienVault OTX General

Description

On March 31, NSFOCUS CERT detected that the npm repository of the HTTP client library Axios was poisoned by the supply chain. The attacker bypassed the normal GitHub Actions CI/CD pipeline of the project, changed the account email address of the axios maintainer to an anonymous ProtonMail address, and manually released a malicious version with a Trojan backdoor through the npm CLI. When the user installs it, a persistent remote control will be established on the host. The impact is wide-ranging, and relevant users are requested to take measures for investigation and protection as soon as possible.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 04/01/2026, 15:24:34 UTC

Technical Analysis

The Axios Front-End Library npm supply chain poisoning incident involves a sophisticated compromise of the Axios npm package repository. The attacker circumvented the standard GitHub Actions CI/CD pipeline security controls, gaining unauthorized access to the maintainer's account by changing the registered email to an anonymous ProtonMail address. This allowed the adversary to manually publish a malicious Axios package version containing a Trojan backdoor. Upon installation via the npm CLI, the malicious package executes code that establishes a persistent remote control channel on the victim's host, enabling attackers to execute arbitrary commands and potentially exfiltrate data or pivot within networks. The attack leverages the trust developers place in popular open-source dependencies, exploiting the supply chain to distribute malware at scale. The incident was detected by NSFOCUS CERT, which issued alerts and published indicators of compromise including file hashes and malicious domains used for command and control. No CVE or known active exploits have been reported yet, but the threat underscores the criticality of securing CI/CD pipelines, verifying package integrity, and monitoring for anomalous package releases in open-source projects.

Potential Impact

This supply chain attack on Axios poses a significant risk to organizations worldwide due to Axios's widespread adoption in web and server applications. The Trojan backdoor enables persistent remote access, potentially compromising confidentiality, integrity, and availability of affected systems. Attackers could steal sensitive data, deploy ransomware, or use compromised hosts as footholds for further network intrusion. The attack undermines trust in the npm ecosystem and open-source supply chains, potentially affecting thousands of development projects and production environments. Organizations relying on Axios without verification of package authenticity are particularly vulnerable. The incident could lead to operational disruptions, data breaches, and reputational damage. Given the broad usage of Axios across industries, the impact could be extensive if malicious versions are widely installed before detection and remediation.

Mitigation Recommendations

1. Immediately audit all systems and development environments for the installation of any suspicious or unexpected Axios package versions, using the provided malicious hashes for detection. 2. Revert to a known good Axios version from a verified source and avoid installing any versions released after March 31, 2026, until official patches or statements are issued. 3. Implement strict verification of package integrity using cryptographic signatures or checksum validation before deployment. 4. Enhance CI/CD pipeline security by enforcing multi-factor authentication, restricting permissions, and monitoring for unauthorized changes to maintainer accounts and repository settings. 5. Monitor network traffic for connections to identified malicious domains (callnrwise.com, sfrclak.com) and URLs to detect potential command and control communications. 6. Educate development teams about supply chain risks and encourage use of tools that scan dependencies for known vulnerabilities or malicious code. 7. Collaborate with npm and Axios maintainers to track updates and apply official patches promptly once available. 8. Consider implementing runtime application self-protection (RASP) or endpoint detection and response (EDR) solutions to detect anomalous behaviors caused by backdoors.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://nsfocusglobal.com/axios-front-end-library-npm-supply-chain-poisoning-alert/"]
Adversary
null
Pulse Id
69cd1aa5d630ea626fc62588
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash07d889e2dadce6f3910dcbc253317d28ca61c766
hash2553649f2322049666871cea80a5d0d6adc700ca
hashd6f3f62fd3b9f5432f5782b62d8cfd5247d5ee71

Url

ValueDescriptionCopy
urlhttp://sfrclak.com:8000/6202033

Domain

ValueDescriptionCopy
domaincallnrwise.com
domainsfrclak.com

Threat ID: 69cd34f2e6bfc5ba1dda89f6

Added to database: 4/1/2026, 3:08:34 PM

Last enriched: 4/1/2026, 3:24:34 PM

Last updated: 4/6/2026, 9:10:07 AM

Views: 290

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses