Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2589 articles · 106325 vulns · 36/41 feeds (7d)
← Back to list
EST
PRE-CVEEXPLOITED

Malicious Dependency Injection in Axios NPM Package

60% confidence

Description

A supply chain attack compromised the Axios NPM package by injecting a malicious dependency 'plain-crypto-js' into versions 1.14.1 and 0.30.4. This dependency acts as an obfuscated dropper for the WAVESHAPER.V2 backdoor, targeting Windows, macOS, and Linux systems.

Affected Products

VendorProductVersions
—axios1.14.1, 0.30.4

Related News (1 articles)

Tier C
Mandiant Blog11h ago
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
PublishedMar 31, 2026
Last enriched2h ago
Tags
supply chain attacknpmbackdoorunc1069
Trending Score38
Source articles1
Independent1
Info Completeness6/14
Missing: cve_id, vendor, cvss, epss, cwe, kev, patch, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: reported
Confidence: 60%

Vulnerability Timeline

CVE Published
Mar 31, 2026
Actively Exploited
Mar 31, 2026
Exploit Available
Mar 31, 2026
Discovered by ZDM
Mar 31, 2026