On March 31, 2026 (UTC), the primary npm maintainer account (jasonsaayman) for the axios HTTP client was compromised. The attacker published two malicious versions:
axios@1.14.1(taggedlatest)axios@0.30.4(taggedlegacy)
Both versions inject a hidden dependency (plain-crypto-js@4.2.1) that executes a postinstall hook dropping a cross-platform Remote Access Trojan (RAT). The malware self-destructs and replaces its own package.json to hide evidence.