← Volver a todas las noticias

Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account

Attackers compromised a maintainer account for the widely used axios npm package and pushed a malicious release containing a cross-platform remote access trojan, exposed to millions of automated installs before npm revoked it.

Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account

Attackers compromised a maintainer account for the widely used axios npm package, downloaded over 5 million times per week, and pushed a malicious release containing a cross-platform remote access trojan (RAT). The trojan targeted Windows, Linux, and macOS environments, giving attackers persistent backdoor access to any system that automatically updated the dependency.

The malicious version remained available for several hours before npm revoked it — a window sufficient for millions of automated installs across CI/CD pipelines and developer environments worldwide.

What this means for your organisation: compromising a widely-used open source package is an efficient attack — you reach every developer, CI/CD pipeline, and deployment that pulls an automatic update without touching individual targets at all. The axios incident should prompt any development team to check whether they're pinning dependencies to verified versions and whether they have visibility into their software supply chain. NIS2 and DORA both treat ICT supply chain risk as a first-class obligation for a reason.

Fuente: The Hacker News

¿Quiere esto para su organización?