A government website registered with the Digital Government Authority

AXIOS NPM Alert

Share the page

Copy link
تنبيه AXIOS NPM
AXIOS NPM Alert

Warning Number:

2026-7391

Severity Level

Critical

Warning Date

07/04/2026

480

Target sector

Media
Other
Education
Communication and information technology
HealthCare
Commercial Facilities
Defence
Manufacturing
Finance and Economy
Government Facilities
Water and Utilities
Transportation
Commerce and Investment
Energy

Description

Malicious code injected in AXIOS NPM package. The injected malicious code allows the attacker to perform unauthorized modification on the affected applications.

 

Affected Packages:
•    axios@1.14.1
•    axios@0.30.4

Best Practice And Recommendations

The CERT team encourages users to perform the following:

 

1.    Clear NPM cache for the package manager.
2.    Reinstall the affected package with an unaffected version.
3.    Remove the dependency (plain-crypto-js)
4.    Review the logs of the affected systems to rule out any suspicious activities or connections to the related IoCs. If a malicious activity is detected; Isolate the affected system, activate the incident response plan.
5.    Reset all credentials and access tokens on the affected systems.

Last Update at: 07/04/2026 - 9:10pm Saudi time

Was this page useful?

0% of users said Yes from 0 Feedbacks