Free tools Windows power users keep installed
One-click scans. No signup required.
Axios was compromised in a March 31, 2026 npm supply-chain attack: two releases carried a hidden dependency that ran an install-time script to download a remote access trojan (RAT) for Windows, macOS and Linux. If an affected release was installed on a developer machine or in CI/CD, treat that environment as potentially compromised. Removing the package is not enough to establish that the host is safe.
Which Axios versions were affected?
The affected releases identified in advisories were axios@1.14.1 and axios@0.30.4. Both added plain-crypto-js@4.2.1, the dependency used to trigger the malicious install behavior. The Axios maintainer and CISA identified these versions; the evidence for this incident does not establish other Axios releases as affected.
Look beyond the current package manifest. A vulnerable version may have been installed in a past build, preserved in a lockfile, cached in an artifact repository, or pulled into a developer environment during an update. An affected version in a file is a reason to investigate; installation logs and other records can help determine whether an install actually ran.
What happened during the attack?
Axios maintainer Jason Saayman reported that attackers published the two releases through his compromised npm account. Microsoft Threat Intelligence says the Axios application logic itself was not changed: the added dependency was not imported by Axios’s normal runtime code, but its install-time script was designed to retrieve a second-stage RAT. That distinction matters: an application could appear to work normally even though a malicious action had occurred during npm install or npm update.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute#1 Best Overall
The dropper selected a payload for the host operating system. Elastic Security Labs describes observed behavior in which Node spawned an OS-native shell or interpreter to retrieve and execute a payload in a hidden or detached context. Microsoft also reports that the installer removed its loader and replaced the package manifest after launching the payload. Because of that anti-forensic behavior, a later inspection of node_modules may not show a complete record of what happened.
Microsoft Threat Intelligence attributed the compromise and related infrastructure to Sapphire Sleet, a North Korean state actor. This is Microsoft’s attribution, not a universally confirmed finding. The maintainer said a targeted social-engineering campaign and RAT infection of his PC led to the npm credential compromise, but that the initial compromise timeline and access method were still under investigation.
When were the malicious releases available?
According to the maintainer’s reported timeline, plain-crypto-js@4.2.0 appeared on March 30, 2026; axios@1.14.1 was published at 00:21 UTC on March 31, followed by axios@0.30.4 at about 01:00 UTC. The maintainer reported removing the Axios releases at 03:15 UTC and plain-crypto-js at 03:29 UTC. He described the exposure as roughly three hours. These are reported publication and removal times, not a count of successful installations or infected machines.
The attack’s potential reach should not be confused with confirmed victim numbers. In separate analyses published April 1, 2026, Elastic Security Labs estimated approximately 100 million weekly Axios downloads, while Microsoft Threat Intelligence cited over 70 million weekly downloads. These are the respective organizations’ estimates at that time; they differ and neither is a current verified download count or a measure of infections.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsHow to check whether a developer machine or pipeline was exposed
Review systems and records that may have resolved or installed dependencies during the exposure window. The relevant scope includes more than production servers:
- Application repositories, manifests, lockfiles and dependency-update records.
- CI/CD jobs, build agents, developer workstations and any ephemeral runners that performed installs or updates.
- Artifact repositories, package proxies and dependency-management caches that could retain a malicious package.
- Install logs, process telemetry, network egress records and build output for the affected period.
Check package records for the named affected versions and dependency. Then look for installation-time behavior such as Node starting an unexpected shell or interpreter, retrieving an unfamiliar payload, or executing a child process in a hidden or detached context. A missing package directory or a clean-looking manifest after the event does not by itself prove that the machine was never affected.
What to do if an affected version was installed
CISA’s April 20, 2026 alert recommends reviewing repositories, CI/CD pipelines, developer machines, artifact repositories and dependency caches; restoring affected environments to a known-safe state; and rotating credentials that may have been exposed. Apply the steps in an order that prevents further installs and limits ongoing access:
- Stop further resolution of the malicious releases. Pin Axios to
1.14.0or0.30.3, as CISA recommends, and update lockfiles accordingly. Removenode_modules/plain-crypto-js/where present. Check that package manifests, lockfiles, caches and internal mirrors cannot reintroduce the affected versions. - Contain and investigate the environment. If a machine or build ran an affected install, treat it as potentially compromised. Preserve relevant logs and investigate the host and pipeline for additional activity; restore the environment to a known-safe state rather than relying on package deletion alone. For CI, include ephemeral jobs and any downstream artifacts produced by the affected run.
- Revoke or rotate potentially exposed credentials. Consider VCS tokens, CI/CD secrets, cloud keys, npm tokens and SSH keys available to the affected machine or job. Rotate secrets injected into an affected ephemeral CI run as well as credentials stored on persistent systems.
- Hunt for network, process and filesystem evidence. Review installation-time process activity, outbound connections and relevant egress logs. Use published indicators alongside behavior-based checks; indicators are leads for investigation, not a complete inventory of possible artifacts.
- Monitor normal build behavior. CISA recommends baselining expected activity for tools that use Axios and alerting on unexpected container builds, shell enablement or command execution.
Deleting node_modules/plain-crypto-js/ removes the dependency directory, not necessarily a RAT that its script already downloaded or executed. Whether further malware remains cannot be determined from package removal alone; assess the affected host and restore it to a known-safe state if compromise is suspected.
Best Value
Published indicators to support an investigation
The Cyber Security Agency of Singapore (CSA) advisory, dated April 1 and updated October 4, 2026, lists the following indicators. Treat them according to your organization’s procedures and check the current advisory for updates. The listed paths and addresses are defanged here; these indicators are not an exhaustive set of possible artifacts.
- Packages:
axios@1.14.1,axios@0.30.4andplain-crypto-js@4.2.1. The CSA advisory also lists package shasums. - Network:
sfrclak[.]com,142[.]11[.]206[.]73andhttp[:]//sfrclak[.]com:8000/6202033. - macOS filesystem:
/Library/Caches/com[.]apple[.]act[.]mond. - Windows filesystem:
%PROGRAMDATA%wt.exeandsystem.bat. - Linux filesystem:
/tmp/ld[.]py.
CISA specifically calls out Sfrclak[.]com. Elastic’s analysis recommends behavior-based detection, including monitoring for Node processes that launch native execution paths and retrieve payloads. A match on an indicator warrants investigation; the absence of a match does not establish that a system is clean.
Why the incident matters beyond Axios
The attack used trust in a widely used package and its maintainer account to reach environments that install dependencies. Since the malicious behavior ran at installation time rather than through Axios’s ordinary application logic, normal application tests could miss it. The same exposure question applies to build infrastructure as well as developer laptops: any environment that ran the install may have had access to secrets, source code or deployment credentials.
The practical response is therefore broader than changing one dependency: verify package and lockfile state, examine machines and pipelines that ran installs, investigate for execution and network activity, and revoke credentials that may have been accessible. The cited advisories offer response guidance and indicators, but a published indicator list cannot substitute for an environment-specific investigation.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

