Return to Global Matrix
CLASSIFIED: EYES ONLY

Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account

TELEMETRY SUMMARY DECRYPTION

Tactical Briefing: Axios HTTP client has been compromised through a supply chain attack, introducing malicious dependency "plain-crypto-js" version 4.2.1 in versions 1.14.1 and 0.30.4. The attack was executed via the exploitation of compromised npm credentials belonging to Axios. Immediate assessment and mitigation of affected systems are advised to prevent further infiltration.

This briefing snippet has been strictly truncated for global aggregation. Operators must securely establish a dedicated intelligence uplink below to access the full operational report exactly as authored by the origin network.

SAT-COM 4LAT: 45.192LON: 34.021UTC: 2026-03-31

Event Telemetry

STATUS IDENTIFIERCRITICAL EVENT
ORIGIN DESKCYBER
ACQUISITION TIME12:04 ZULU
AUTHORSYSTEM.AUTO[992]