The Axios Supply Chain Attack Explained: How a Compromised npm Account Put 83 Million Projects at Risk
On March 31, 2026, two malicious versions of Axios — the most widely used HTTP client in JavaScript with 83 million weekly downloads — were briefly published to npm via a compromised maintainer account. They contained a cross-platform remote access trojan. Here's exactly what happened and what you need to do.