A government website registered with the Digital Government Authority

AXIOS NPM Alert

Share the page

Copy link
تنبيه AXIOS NPM
AXIOS NPM Alert

Warning Number:

2026-7391

Severity Level

Critical

Warning Date

07/04/2026

440

Target sector

Energy
Government Facilities
Education
Water and Utilities
Commercial Facilities
Manufacturing
Finance and Economy
Defence
HealthCare
Other
Media
Communication and information technology
Commerce and Investment
Transportation

Description

Malicious code injected in AXIOS NPM package. The injected malicious code allows the attacker to perform unauthorized modification on the affected applications.

 

Affected Packages:
•    axios@1.14.1
•    axios@0.30.4

Best Practice And Recommendations

The CERT team encourages users to perform the following:

 

1.    Clear NPM cache for the package manager.
2.    Reinstall the affected package with an unaffected version.
3.    Remove the dependency (plain-crypto-js)
4.    Review the logs of the affected systems to rule out any suspicious activities or connections to the related IoCs. If a malicious activity is detected; Isolate the affected system, activate the incident response plan.
5.    Reset all credentials and access tokens on the affected systems.

Last Update at: 07/04/2026 - 9:10pm Saudi time

Was this page useful?

0% of users said Yes from 0 Feedbacks