Post

HN
Hacker News

Post Mortem: axios NPM supply chain compromise

There was an error while loading. Please reload this page .

Date: March 31, 2026 Author: Jason Saayman Status: Remediation in progress

On March 31, 2026, two malicious versions of axios (1.14.1 and 0.30.4) were published to the npm registry through my compromised account. Both versions injected a dependency called plain-crypto-js@4.2.1 that installed a remote access trojan on macOS, Windows, and Linux.

The malicious versions were live for about 3 hours before being removed.

If anything comes back, treat that machine as compromised:

If you were already pinned to a clean version and didn't run a fresh install between 00:21 and 03:15 UTC on March 31, you're fine.