{"id":29200,"date":"2026-03-31T16:22:17","date_gmt":"2026-03-31T16:22:17","guid":{"rendered":"https:\/\/microvibenews.com\/?p=29200"},"modified":"2026-03-31T16:22:17","modified_gmt":"2026-03-31T16:22:17","slug":"hacker-hijacks-axios-open-source-project-used-by-millions-to-push-malware","status":"publish","type":"post","link":"https:\/\/microvibenews.com\/?p=29200","title":{"rendered":"Hacker hijacks Axios open-source project, used by millions, to push malware"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">A hacker has hijacked and modified a popular open-source software development tool to deliver malware that could put millions of developers at risk of being compromised.<\/p>\n<p class=\"wp-block-paragraph\">On Monday, a hacker pushed malicious versions of the widely used JavaScript library called Axios, which developers rely on to allow their software to connect to the internet. The affected library was <a rel=\"nofollow\" href=\"https:\/\/www.npmjs.com\/package\/axios\">hosted on npm<\/a>, a software repository that stores code for open-source projects. Axios is downloaded <a rel=\"nofollow\" href=\"https:\/\/security.snyk.io\/package\/npm\/axios#:~:text=WEEKLY%20DOWNLOADS%20(100.3M)\">tens of millions of times<\/a> every week.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The hijack was spotted and stopped in around three hours overnight on Monday into Tuesday, according to security firm StepSecurity, <a rel=\"nofollow\" href=\"https:\/\/www.stepsecurity.io\/blog\/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan#:~:text=had%20been%20live%20for%20approximately%202%20hours%2053%20minutes\">which analyzed the attack<\/a>.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Hackers are increasingly targeting developers of popular open-source projects in an effort to mass-hack anyone who relies on the compromised code, potentially granting the hackers access to vast numbers of affected devices. These kinds of widespread breaches are called <a href=\"http:\/\/techcrunch.com\/2022\/11\/29\/software-supply-chain-security-is-broader-than-solarwinds-and-log4j\/\">supply chain attacks<\/a> because they target software that allows hackers to then hack whoever downloaded the compromised software. In recent years, hackers have targeted companies like <a href=\"https:\/\/techcrunch.com\/2023\/03\/30\/theres-a-new-supply-chain-attack-targeting-customers-of-a-phone-system-with-12-million-users\/\">3CX<\/a>, <a href=\"https:\/\/techcrunch.com\/2021\/07\/05\/kaseya-hack-flood-ransomware\/\">Kaseya<\/a>, and <a href=\"https:\/\/techcrunch.com\/2020\/12\/21\/after-the-fireeye-and-solarwinds-breaches-whats-your-failsafe\/\">SolarWinds<\/a>, as well as open source tools such as <a href=\"https:\/\/techcrunch.com\/2021\/12\/10\/apple-icloud-twitter-and-minecraft-vulnerable-to-ubiquitous-zero-day-exploit\/\">Log4j<\/a> and <a href=\"http:\/\/techcrunch.com\/2024\/10\/22\/researchers-link-polyfill-supply-chain-attack-to-huge-network-of-copycat-gambling-sites\/\">Polyfill.io<\/a>, to target large numbers of their users.<\/p>\n<p class=\"wp-block-paragraph\">It\u2019s unclear at this point how many people downloaded the malicious version of Axios during that timespan. Security company Aikido, which <a rel=\"nofollow\" href=\"https:\/\/www.aikido.dev\/blog\/axios-npm-compromised-maintainer-hijacked-rat\">also investigated the incident<\/a>, said anyone who downloaded the code \u201cshould assume their system is compromised.\u201d<\/p>\n<div class=\"article-block block--callout block--right has-green-500-background-color\">\n<h4 class=\"block--callout__title\">Contact Us<\/h4>\n<p>\t\t\tDo you have more information about this hack? Or other supply chain attacks? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram, Keybase and Wire @lorenzofb, or <a href=\"https:\/\/techcrunch.com\/2026\/03\/31\/hacker-hijacks-axios-open-source-project-used-by-millions-to-push-malware\/mailto:lorenzo@techcrunch.com\/\">by email<\/a><a href=\"https:\/\/techcrunch.com\/2026\/03\/31\/hacker-hijacks-axios-open-source-project-used-by-millions-to-push-malware\/mailto:lorenzo@techcrunch.com\/\">.<\/a> \t\t<\/div>\n<p class=\"wp-block-paragraph\">The hacker was able to slip malicious code inside Axios by compromising the account of one of the project\u2019s primary developers, who was authorized to push out updates. The hacker replaced the legitimate developer\u2019s email address on the account with their own, making it more difficult for the developer to regain access.<\/p>\n<p class=\"wp-block-paragraph\">Once in control of the account, the hacker inserted malicious code designed to deliver a remote access trojan, or RAT \u2014 essentially malware that can give hackers full, remote control of a victim\u2019s computer. The hacker then pushed out new versions of Axios in a legitimate-looking update for Windows, macOS, and Linux users.\u00a0<\/p>\n<div class=\"wp-block-techcrunch-inline-cta\">\n<div class=\"inline-cta__wrapper\">\n<p>Techcrunch event<\/p>\n<div class=\"inline-cta__content\">\n<p>\n\t\t\t\t\t\t\t\t\t<span class=\"inline-cta__location\">San Francisco, CA<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"inline-cta__separator\">|<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"inline-cta__date\">October 13-15, 2026<\/span>\n\t\t\t\t\t\t\t<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<p class=\"wp-block-paragraph\">The hackers also designed the malware, as well as some of the code used to deliver it, to automatically delete itself after installation in an attempt to hide from anti-malware engines and investigators, according to security researchers.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2026\/03\/31\/hacker-hijacks-axios-open-source-project-used-by-millions-to-push-malware\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A hacker has hijacked and modi&hellip; <\/p>\n","protected":false},"author":1,"featured_media":29201,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[249],"tags":[16801,4437,1662,3210,1665,1666,6112,16802],"_links":{"self":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts\/29200"}],"collection":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=29200"}],"version-history":[{"count":0,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts\/29200\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/media\/29201"}],"wp:attachment":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=29200"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=29200"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=29200"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}