Axios versions 1.14.1 & 0.30.4 were compromised, injecting malicious plain-crypto-js v4.2.1. The trojan targets Windows, macOS, & Linux—stay alert! #cybersecurity #opensource https://thehackernews.com/2026/03/axios-supply-chain-attack-pushes-cross.html

Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account
Axios 1.14.1 and 0.30.4 injected malicious [email protected] after npm compromise on March 31, 2026, deploying cross-platform RAT malware.