What's Hot

    Uniblock Raises $5.2M to Unify Blockchain Infrastructure

    03/31/2026

    Bitcoin Faces Fresh Pressure As Oil Crosses $104 For First Time In 4 Years

    03/31/2026

    Singapore Court Order Follows Curve Dispute After Resupply Exploit

    03/31/2026
    Facebook Twitter Instagram
    • Business
    • Markets
    • Get In Touch
    • Our Authors
    Facebook Twitter Instagram
    Cryptomarketnews
    • Home
    • Business

      US Users Barred From KuCoin After $500K CFTC Settlement

      03/31/2026

      Google Quantum Paper Boosts Odds of Bitcoin ‘Q-Day’ by 2032, Researchers Warn

      03/31/2026

      New US Rule Seeks to Open $8T Retirement Market to Crypto

      03/31/2026

      US Charges Hacker Behind $53 Million Uranium Finance Exploit

      03/31/2026

      Chainlink Labs, Anchorage Digital Back New Crypto Super PAC Ahead of Midterms

      03/30/2026
    • Technology
      1. Business
      2. Insights
      3. View All

      US Users Barred From KuCoin After $500K CFTC Settlement

      03/31/2026

      Google Quantum Paper Boosts Odds of Bitcoin ‘Q-Day’ by 2032, Researchers Warn

      03/31/2026

      New US Rule Seeks to Open $8T Retirement Market to Crypto

      03/31/2026

      US Charges Hacker Behind $53 Million Uranium Finance Exploit

      03/31/2026

      Singapore Court Order Follows Curve Dispute After Resupply Exploit

      03/31/2026

      XRP, SOL and ADA price outlook as BTC struggles ahead of key macro events

      03/31/2026

      Bitcoin Range Traps Traders At $65K — Are Long‑Term Holders Finally Surrendering?

      03/31/2026

      Bitcoin treasury company sells $20M BTC at a loss as its stock collapses after buying at $118k

      03/31/2026

      Uniblock Raises $5.2M to Unify Blockchain Infrastructure

      03/31/2026

      Bitcoin Holds $66K as Trump Prioritizes Iran War Exit Over Reopening Hormuz

      03/31/2026

      Senator Questions SEC Over Treatment of Trump-Linked Crypto Businesses

      03/30/2026

      Qwen 3.5 Omni: Alibaba’s AI Model Can Now Hear, Watch, and Clone Your Voice

      03/30/2026
    • Insights
      1. Bitcoin
      2. Ethereum
      3. Eurozone
      4. Monero
      5. View All

      Singapore Court Order Follows Curve Dispute After Resupply Exploit

      03/31/2026

      Axios NPM Package Compromised in Supply Chain Attack

      03/31/2026

      Dynamic Adds TON Wallet Infrastructure for Telegram Mini Apps

      03/31/2026

      F2Pool Co-Founder’s 2,900 BTC Condo Sells for 7 BTC

      03/31/2026

      Labor Department Proposal Could Open 401(k)s To Bitcoin And Alternative Assets

      03/30/2026

      U.S. Senators Unveil Landmark Bitcoin Mining, Reserve Bill

      03/30/2026

      American Bitcoin (ABTC) Surpasses 7,000 Bitcoin

      03/30/2026

      Bitcoin Fear And Greed Index Hits Extreme Fear At 13

      03/27/2026

      Bitcoin Range Traps Traders At $65K — Are Long‑Term Holders Finally Surrendering?

      03/31/2026

      Here Are The Main Levels To Watch After Dogecoin Price Completed A Clean Kumo Rejection

      03/31/2026

      Google Says End For Bitcoin Is Near? Quantum Computers Could Attack Crypto This Soon

      03/31/2026

      Is XRP Quietly Being Accumulated? Here’s The Data

      03/31/2026

      Bitcoin treasury company sells $20M BTC at a loss as its stock collapses after buying at $118k

      03/31/2026

      Iran Speaker predicts pre-market “reverse indicator” then Bitcoin climbed before the S&P500

      03/30/2026

      Ripple bets privacy and AI can make XRPL fit for institutions

      03/30/2026

      Sports blew up prediction markets. Now it could destroy them

      03/28/2026

      Singapore Court Order Follows Curve Dispute After Resupply Exploit

      03/31/2026

      XRP, SOL and ADA price outlook as BTC struggles ahead of key macro events

      03/31/2026

      Bitcoin Range Traps Traders At $65K — Are Long‑Term Holders Finally Surrendering?

      03/31/2026

      Bitcoin treasury company sells $20M BTC at a loss as its stock collapses after buying at $118k

      03/31/2026
    • Markets
    • Get In Touch
    Cryptomarketnews
    Home»Insights»Videos»Bitcoin»Axios NPM Package Compromised in Supply Chain Attack
    Bitcoin

    Axios NPM Package Compromised in Supply Chain Attack

    adminBy admin03/31/2026No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Two malicious Axios npm releases have prompted warnings for developers to rotate credentials and treat affected systems as compromised after a supply chain attack poisoned the popular JavaScript HTTP client library.

    The compromise was first reported by cybersecurity company Socket, which said axios@1.14.1 and axios@0.30.4 were modified to pull in plain-crypto-js@4.2.1, a malicious dependency that ran automatically during installation before the releases were removed from npm.

    According to security company OX Security, the altered code can give attackers remote access to infected devices, allowing them to steal sensitive data such as login credentials, API keys and crypto wallet information.

    The incident shows how a single compromised open-source component can potentially ripple across thousands of applications that rely on it, exposing not just developers but also platforms and users connected to the system. 

    Security companies urge key rotation, system audits

    OX Security warned developers who installed axios@1.14.1 or axios@0.30.4 to treat their systems as fully compromised and immediately rotate credentials, including API keys and session tokens.

    Socket said the compromised Axios releases were modified to include a dependency on plain-crypto-js@4.2.1, a package published shortly before the incident and later identified as malicious.

    Related: Trust Wallet browser extension knocked offline by Chrome Store ‘bug,’ CEO says

    The company said the dependency was configured to run automatically during installation through a post-install script, allowing attackers to execute code on target systems without additional user interaction.

    Socket advised developers to review their projects and dependency files for the affected Axios versions and the associated plain-crypto-js@4.2.1 package, and to remove or roll back any compromised versions immediately.

    Earlier crypto incidents highlight supply chain risks

    Earlier crypto incidents have shown how supply chain breaches can escalate from stolen developer information to user-facing wallet losses.

    On Jan. 3, onchain investigator ZachXBT reported that “hundreds” of wallets across Ethereum Virtual Machine-compatible networks were drained in a broad attack that siphoned small amounts from each victim. 

    Cybersecurity researcher Vladimir S. said the incident was potentially linked to a December breach affecting Trust Wallet, which resulted in roughly $7 million in losses across over 2,500 wallets. 

    Trust Wallet later said the breach may have originated from a supply chain compromise involving npm packages used in its development workflow.

    Magazine: Nobody knows if quantum secure cryptography will even work