Mitigating the Axios npm supply chain compromise
Incidents: A recent supply chain attack targeting Axios, a widely-used JavaScript HTTP client with over 70 million weekly downloads, highlights the growing sophistication of state-sponsored threats.
Deep Analysis and Expert Commentary
A recent supply chain attack targeting Axios, a widely-used JavaScript HTTP client with over 70 million weekly downloads, highlights the growing sophistication of state-sponsored threats. On March 31, 2026, malicious versions (1.14.1 and 0.30.4) were released, embedding a dependency that connected to a command-and-control (C2) server operated by Sapphire Sleet, a North Korean state actor. Upon con
Original Article Brief Intro
Microsoft Security Blog · 2026-04-01 · Incidents: A recent supply chain attack targeting Axios, a widely-used JavaScript HTTP client with over 70 million weekly downloads, highlights the growing sophistication of state-sponsored threats.
Related Terms and Notes
Malware Families
- remote access trojan
Techniques / TTPs
- Sapphire Sleet — A North Korean state-sponsored threat actor known for cyber espionage and supply chain attacks.
Context Notes
- Axios — A popular JavaScript HTTP client used for making HTTP requests to REST endpoints.
- npm compromise
- Sapphire Sleet