Malicious code in axios-fast (npm)
The npm package axios-fast versions 1.0.0 and 1.0.1 contains malicious code that executes during installation. Specifically, a preinstall script sends all environment variables from the installing machine to an attacker-controlled webhook URL. This can expose sensitive secrets such as AWS credentials, NPM tokens, and GitHub tokens. The package is a typosquat of the popular axios HTTP client and does not provide legitimate functionality beyond this exfiltration.
AI Analysis
Technical Summary
The axios-fast package versions 1.0.0 and 1.0.1 include a preinstall lifecycle script that runs automatically during npm install. This script executes a Node.js one-liner that posts the entire process environment variables to a hardcoded webhook.site URL controlled by an attacker. This behavior results in the exfiltration of potentially sensitive environment variables, including CI/build secrets like AWS_*, NPM_TOKEN, and GH_TOKEN. The package is malicious and designed to harvest secrets rather than provide useful functionality.
Potential Impact
Installation of axios-fast versions 1.0.0 or 1.0.1 can lead to the disclosure of all environment variables on the host machine to a third party. This includes sensitive credentials and tokens commonly used in continuous integration and deployment pipelines, potentially leading to unauthorized access to cloud resources, package repositories, and source code management systems.
Mitigation Recommendations
Avoid using the axios-fast package entirely. Since this is a malicious package, the best mitigation is to remove it from any dependency trees and replace it with the legitimate axios package or other trusted alternatives. There is no official patch or fix for this package; remediation involves removing the package and auditing for any leaked secrets. Rotate any credentials that may have been exposed if this package was installed.
Malicious code in axios-fast (npm)
Description
The npm package axios-fast versions 1.0.0 and 1.0.1 contains malicious code that executes during installation. Specifically, a preinstall script sends all environment variables from the installing machine to an attacker-controlled webhook URL. This can expose sensitive secrets such as AWS credentials, NPM tokens, and GitHub tokens. The package is a typosquat of the popular axios HTTP client and does not provide legitimate functionality beyond this exfiltration.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The axios-fast package versions 1.0.0 and 1.0.1 include a preinstall lifecycle script that runs automatically during npm install. This script executes a Node.js one-liner that posts the entire process environment variables to a hardcoded webhook.site URL controlled by an attacker. This behavior results in the exfiltration of potentially sensitive environment variables, including CI/build secrets like AWS_*, NPM_TOKEN, and GH_TOKEN. The package is malicious and designed to harvest secrets rather than provide useful functionality.
Potential Impact
Installation of axios-fast versions 1.0.0 or 1.0.1 can lead to the disclosure of all environment variables on the host machine to a third party. This includes sensitive credentials and tokens commonly used in continuous integration and deployment pipelines, potentially leading to unauthorized access to cloud resources, package repositories, and source code management systems.
Mitigation Recommendations
Avoid using the axios-fast package entirely. Since this is a malicious package, the best mitigation is to remove it from any dependency trees and replace it with the legitimate axios package or other trusted alternatives. There is no official patch or fix for this package; remediation involves removing the package and auditing for any leaked secrets. Rotate any credentials that may have been exposed if this package was installed.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14029
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7f43efbf8831d5395d7188
Added to database: 08/14/2026, 16:35:59 UTC
Last enriched: 08/14/2026, 16:43:26 UTC
Last updated: 08/14/2026, 16:43:26 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.