GHSA-3hfp-gqgh-xc5g
CRITICALA supply chain attack on the axios npm package (versions 1.14.1 and 0.30.4) introduced a malicious transitive dependency (plain-crypto-js@4.2.1) that deploys a cross-platform remote access trojan (RAT) on macOS, Windows, and Linux. The attacker compromised the primary axios maintainer's npm account to publish the malicious versions.
- Affected
- >= 0.1800.0, < 0.2695.1, >=0.1800.0, <0.2695.1
- Fixed in
- 0.2695.1
- Weakness
- CWE-508
- Published
- 2026-04-02
- Source
- github
GHSAreferencereferencereferencereferencereferencereferencereferencereference