Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3879 articles · 205847 vulns · 37/41 feeds (7d)
← Back to list
EST
PRE-CVE
axios · axios npm package

Malicious Code Injection via Axios npm Package Maintainer Account Takeover

85% confidence

Description

The Axios npm package was compromised through a maintainer account takeover, resulting in the publication of malicious versions 1.14.1 and 0.30.4. These versions introduced a hidden dependency (plain-crypto-js@4.2.1) that executes a post-install script deploying a cross-platform Remote Access Trojan (RAT) on Windows, macOS, and Linux systems, enabling unauthorized code execution.

Affected Products

VendorProductVersions
axiosaxios npm package1.14.1, 0.30.4

Related News (1 articles)

Tier A
Fortinet PSIRT137d ago
Axios npm Package Compromised
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
CWECWE-254
PublishedApr 14, 2026
Last enriched137d ago
Tags
supply chainnpmmalicious codepost-install scriptratcross-platform
Trending Score0
Source articles1
Independent1
Info Completeness9/14
Missing: cve_id, epss, kev, patch, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-44488EXP
Axios: Allocation of Resources Without Limits or Throttling in axios
Trending: 66
HIGHCVE-2026-44496
Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
Trending: 54
HIGHCVE-2026-44486
Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
Trending: 53
NONECVE-2026-44487EXP
Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
Trending: 52
NONECVE-2026-67313
axios 0.28.0 before 1.18.0 Denial of Service via formDataToJSON
Trending: 18

Pin to Dashboard

Verification

State: verified
Confidence: 85%

Vulnerability Timeline

CVE Published
Apr 14, 2026
Exploit Available
Apr 14, 2026
Discovered by ZDM
Apr 14, 2026