# Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT

DevFeed: [Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT](<https://devfeed.tech/articles/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform-rat-7839.md>)

Original publisher: [Read original article](<https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/>)

Author: Liran Tal

Published: 2026-03-30T23:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [StreamRAT](<https://devfeed.tech/topics/streamrat.md>), [cross-platform](<https://devfeed.tech/topics/cross-platform.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [ide](<https://devfeed.tech/topics/ide.md>), [client](<https://devfeed.tech/topics/client.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [c2](<https://devfeed.tech/tags/c2.md>), [ci](<https://devfeed.tech/tags/ci.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [code](<https://devfeed.tech/tags/code.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [github](<https://devfeed.tech/tags/github.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware](<https://devfeed.tech/tags/malware.md>), [obfuscation](<https://devfeed.tech/tags/obfuscation.md>), [payload](<https://devfeed.tech/tags/payload.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [security](<https://devfeed.tech/tags/security.md>), [server](<https://devfeed.tech/tags/server.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

## AI overview

The article analyzes a supply-chain attack in which malicious Axios versions published to npm through a compromised maintainer account introduced a hidden dependency. Installing the affected packages could trigger a postinstall dropper that downloaded a platform-specific remote access trojan, contacted a command-and-control server, and erased evidence after execution.

## Source excerpt

Meta description: Malicious versions of the Axios npm package (1.14.1 and 0.30.4) were published via a compromised maintainer account, injecting a hidden dependency that deploys a cross-platform remote access trojan. Here's what happened, who's affected, and how to check your exposure.