A government website registered with the Digital Government Authority

AXIOS NPM Alert

تنبيه AXIOS NPM
AXIOS NPM Alert

Warning Number:

2026-7391

Severity Level

Critical

Warning Date

07/04/2026

130

Target sector

Manufacturing
Other
Commerce and Investment
Education
Transportation
Communication and information technology
Energy
Government Facilities
HealthCare
Commercial Facilities
Finance and Economy
Media
Defence
Water and Utilities

Description

Malicious code injected in AXIOS NPM package. The injected malicious code allows the attacker to perform unauthorized modification on the affected applications.

 

Affected Packages:
•    axios@1.14.1
•    axios@0.30.4

Best Practice And Recommendations

The CERT team encourages users to perform the following:

 

1.    Clear NPM cache for the package manager.
2.    Reinstall the affected package with an unaffected version.
3.    Remove the dependency (plain-crypto-js)
4.    Review the logs of the affected systems to rule out any suspicious activities or connections to the related IoCs. If a malicious activity is detected; Isolate the affected system, activate the incident response plan.
5.    Reset all credentials and access tokens on the affected systems.

Share the page

Copy link

Last Update at: 07/04/2026 - 9:10pm Saudi time

Was this page useful?

0% of users said Yes from 0 Feedbacks