Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    CLARITY Act Clears Senate Banking Committee 15-9 Here’s What Every Crypto Leader Is Saying
    CLARITY Act Clears Senate Banking Committee 15-9: Here’s What Every Crypto Leader Is Saying
    GENIUS Act stablecoin regulation 2026 — US Treasury, OCC, FDIC and NCUA rulemaking on federal vs state oversight
    GENIUS Act at 10 Months: Inside America’s New Stablecoin Rulebook
    $10.8 Million Drained Inside the THORChain Exploit That Froze Cross-Chain DeFi for 13 Hours
    $10.8 Million Drained: Inside the THORChain Exploit That Froze Cross-Chain DeFi for 13 Hours
    BG Wealth and DSJ Exchange collapse exposes 2026 crypto scam pipeline
    How BG Wealth and DSJ Exposed the New Pipeline Model Behind 2026 Crypto Fraud
    Chainalysis’ Regional Director on Asia’s Crypto Growth and Stablecoin Revolution
    Exclusive: Chainalysis’ Regional Director on Asia’s Crypto Growth and Stablecoin Revolution
  • Opinion
    OpinionShow More
    The CLARITY Act The Final Hand — Everyone's Bluffing, Nobody's Folding, and Thursday Changes Everything
    The CLARITY Act: The Final Hand — Everyone’s Bluffing, Nobody’s Folding, and Thursday Changes Everything
    WazirX Debuts ‘Guardians of Trust’ Hub Security Pivot or Distraction from the 15% Debt
    WazirX Debuts ‘Guardians of Trust’ Hub: Security Pivot or Distraction from the 15% Debt?
    What Does Bitcoin Become in a World Questioning the Dollar?
    What Does Bitcoin Become in a World Questioning the Dollar?
    What Happens to the One Asset Designed to Escape Control
    What Happens to the One Asset Designed to Escape Control?
    A System Built on Control, and a Question That Refuses to Settle
    A System Built on Control, and a Question That Refuses to Settle
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Axios Supply Chain Attack Deploys Malicious Dependency via npm

SocketSecurity’s CEO Feross urges developers to use verified safe versions immediately.

Written By:
Kenrodgers Fabian

Reviewed By:
Divya Mistry

Last updated: March 31, 2026 1:22 PM
Published March 31, 2026 1:22 PM
Share
Last updated: March 31, 2026 1:22 PM
Published March 31, 2026 1:22 PM
Axios Supply Chain Attack Deploys Malicious Dependency via npm

Key Highlights

  • Malicious versions of Axios were published with hidden code enabling remote system control.
  • The supply chain attack on Axios spread via compromised npm accounts, affecting millions of weekly downloads.
  • Attackers used fake packages like plain-crypto-js to target apps built on Axios across Windows, Mac, and Linux.

A supply chain attack has hit Axios, a widely used JavaScript HTTP client, putting projects around the world at risk. Versions 1.14.1 and 0.30.4 of Axios include a malicious package, plain-crypto-js@4.2.1, that can run commands on affected systems, steal data, and remain hidden on computers. 

With more than 100 million downloads every week, the vulnerability affects a wide range of applications, from frontend frameworks to backend services. Feross, CEO of SocketSecurity, confirmed on X that the attack is active and warned developers to stick to safe, verified versions immediately.

🚨 CRITICAL: Active supply chain attack on axios — one of npm's most depended-on packages.

The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise.

This is textbook supply chain installer malware. axios…

— Feross (@feross) March 31, 2026

The malicious Axios update did not follow the usual GitHub release process. The compromised versions have no corresponding repository tags, suggesting the attacker bypassed normal publishing checks. At first, Axios maintainers could not revoke access, exposing weaknesses in token security and publishing controls. 

The attacker hijacked the lead maintainer’s npm account, jasonsaayman, and manually published the malicious versions using the npm command line, avoiding the standard release pipeline. Feross warned, “Check your lockfiles, not your disk,” pointing out that the malware deletes itself after installation, leaving no visible trace.

How the attack works

The malicious package plain-crypto-js hides its code using a two-step encryption process. It first reverses Base64-encoded strings and then applies a custom cipher to mask module names, commands, and file paths. When installed, a script called setup.js detects the operating system and delivers platform-specific malware. 

On macOS, it installs a hidden RAT disguised as an Apple system file. Windows machines get a hidden PowerShell script, while Linux systems are infected through a Python script. All versions connect to the same server, sfrclak[.]com, letting attackers stay in control.

Furthermore, two other packages, “@shadanai/openclaw” and “@qqbrowser/openclaw-qbot,” were also found to be distributing the same malware. The packages either contained the malicious plain crypto-js or contained tampered Axios packages. This indicates that a compromised dependency could spread quickly to several packages.

Developer action and broader context

Developers should immediately check their projects for axios@1.14.1, axios@0.30.4, and plain-crypto-js@4.2.1. Any affected packages should be removed or rolled back, and credentials should be changed to prevent further risks. 

This attack is similar to recent PyPI incidents, like LiteLLM, where malicious releases exposed 500,000 user accounts. Supply chain attacks have also targeted cryptocurrency platforms, with attackers misusing cloud credentials, showing how easily sensitive code, cloud systems, and infrastructure can be compromised.

The Axios compromise highlights the growing danger of dependency attacks in modern software. Beyond tightening publishing controls, organizations should use automated scanning and rotate credentials regularly to reduce the risk of cascading breaches.

Also Read: Google Warns Quantum Threat to Bitcoin is Approaching Faster Than Expected

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Cryptocurrency
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Fabian is Crypto Journalist at The Crypto Times
By Kenrodgers Fabian
Follow:
Kenrodgers Fabian is a Content Writer with over 3 years of experience in crypto news, data analysis, and IT. With a degree in Health Records and Information Technology, he brings a structured and analytical approach to digital reporting. Kenrodgers focuses on delivering accurate, informative content that helps readers stay updated on the latest trends in crypto and emerging technologies.
Divya Mistry - Content Editor at The Crypto Times
By Divya Mistry
Follow:
Divya Mistry is a Content Editor with over 9 years of experience in news, PR, marketing, and research. Armed with a Master’s Degree in English Literature from the University of Mumbai, she specializes in crafting and refining long-form content across digital and print platforms. Over the years, Divya has contributed to and shaped content for leading brands across a range of industries, including real estate, healthcare, vertical transport, entertainment, lifestyle, education, EdTech, tech, and finance. Her research work has been featured on platforms like DNA India, Forbes, and Elevator World India. She now brings her editorial and research skills to explore the rapidly evolving world of cryptocurrency.

Latest News

Kraken Bets Bigger on Avalanche With New AVAX Staking
Kraken Bets Bigger on Avalanche With New AVAX Staking
Mark Cuban Says Bitcoin Failed When Markets Needed It Most
Mark Cuban Says Bitcoin Failed When Markets Needed It Most
Global Police Seize Crypto Wallets, Bank Funds in $752M Scam
Global Police Seize Crypto Wallets, Bank Funds in $752M Scam
Coinbase Delists TRIA-PERP, NEO-PERP, and IMP-PERP 
Coinbase Delists TRIA-PERP, NEO-PERP, and IMP-PERP 
Pump.fun Introduces USDC Pairs for Stable Launches
Pump.fun Introduces USDC Pairs for Stable Launches

Find Us on Socials

You may also like

MoonPay Acquires Decent in an Eight-Figure Deal

MoonPay Acquires Decent in an Eight-Figure Deal

THORChain Shares Exploit Report Revealing $10.7M Vault Breach by New Node

THORChain Shares Exploit Report Revealing $10.7M Vault Breach by New Node

Bipartisan PARITY Act Seeks Major Overhaul of US Crypto Tax Rules

Bipartisan PARITY Act Seeks Major Overhaul of US Crypto Tax Rules

Monero DEX RetoSwap Suspends Trading After $2.7M Exploit in Haveno Protocol

Monero DEX RetoSwap Suspends Trading After $2.7M Exploit in Haveno Protocol

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information