← The Log
Security

A poisoned axios update slipped into npm

At the end of March 2026, two malicious versions of axios landed on npm after attackers socially engineered the library's maintainer, faking a Slack workspace and a Teams call to get malware onto his machine. axios ships around 100 million downloads a week and sits under 174,000 other packages, so the blast radius was huge. The tampered releases carried a remote-access trojan that harvested credentials and ran remote commands before the versions were pulled within about three hours.

The uncomfortable lesson: a package you trust can turn hostile between two point releases, and the attack started with a convincing conversation, not a clever exploit.

If your site or app pulls in npm packages, pin exact versions instead of auto-accepting the latest, and add a short waiting period before adopting fresh releases so the industry has time to spot bad ones. Use a lockfile, review what updates change, and treat any surprise "install this to join our call" request as a red flag worth verifying by phone.

Further reading: original source ↗

Want this handled for you?

This is exactly the kind of thing our website security work takes off your plate. Start with a free, no-pressure look at your site.

Come aboard
Get the Log by email

Plain-English notes on web, marketing, and getting found online. Occasional, no spam.