Saudi FlagA government website registered with the Digital Government Authority

AXIOS NPM Alert

Share the page

Copy link
تنبيه AXIOS NPM
AXIOS NPM Alert

Warning Number:

2026-7391

Severity Level

Critical

Warning Date

07/04/2026

1672

Target sector

Commercial Facilities
Communication and information technology
Manufacturing
Government Facilities
Water and Utilities
HealthCare
Commerce and Investment
Media
Other
Education
Defence
Energy
Transportation
Finance and Economy

Description

Malicious code injected in AXIOS NPM package. The injected malicious code allows the attacker to perform unauthorized modification on the affected applications.

 

Affected Packages:
•    axios@1.14.1
•    axios@0.30.4

Best Practice And Recommendations

The CERT team encourages users to perform the following:

 

1.    Clear NPM cache for the package manager.
2.    Reinstall the affected package with an unaffected version.
3.    Remove the dependency (plain-crypto-js)
4.    Review the logs of the affected systems to rule out any suspicious activities or connections to the related IoCs. If a malicious activity is detected; Isolate the affected system, activate the incident response plan.
5.    Reset all credentials and access tokens on the affected systems.

Last Update at: 07/04/2026 - 10:07pm Saudi time

Was this page useful?

0% of users said Yes from 0 Feedbacks