Observed Signal · Apr 2, 2026 · Supply Chain Attack · Source: a16z · Impact: 4/5 · Sentiment: Negative
Axios npm Package Hijacked to Install Backdoor
A malicious supply-chain attack compromised a maintainer account for the widely used Axios npm package, adding a new dependency (plain-crypto-js) whose postinstall script downloaded and executed a remote-access trojan before self-deleting. The article frames this incident as part of a broader acceleration of automated, ecosystem-scale supply-chain attacks enabled by autonomous AI coding agents that install dependencies at machine speed. It describes a related campaign called TeamPCP that began by stealing a Trivy CI token, led to a self-propagating CanisterWorm across 66+ npm packages, and cascaded into Docker Hub, PyPI and the VS Code extension marketplace. Behavioral detection (e.g., Socket) that inspects package actions rather than CVE databases can detect novel malicious packages quickly; Socket detected the suspicious dependency in minutes, while the compromised Axios versions remained live for about three hours before removal. The piece warns that AI agents selecting and installing dependencies autonomously expands the attack surface and compresses the window for human review.
This incident illustrates a fast, automated software supply-chain attack that leverages AI-driven dependency selection and compromised CI tokens to cascade across major developer ecosystems (npm, Docker Hub, PyPI). It affects foundational developer infrastructure and increases systemic risk for any industry (including AdTech) that depends on open-source packages and automated agent workflows.
Track NPM Capital Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- An attacker compromised a maintainer account for the Axios npm package and published a version that added a malicious dependency named plain-crypto-js.
- The plain-crypto-js package executed a postinstall script that detected OS, downloaded a remote-access trojan tailored to the machine, executed it, and then deleted itself.
- Axios is heavily used (over 100 million downloads per week), and the compromised versions were available for about three hours before npm removed them.
- A separate campaign called TeamPCP started by stealing a Trivy CI access token, enabling a worm (CanisterWorm) that propagated across 66+ npm packages and cascaded to Docker Hub, PyPI, and the VS Code extension marketplace within eight days.
- Behavioral detection that analyzes package actions (e.g., network access, postinstall scripts) can catch novel malicious packages without prior CVEs; Socket reportedly detected the malicious dependency within six minutes.
Connected Companies & Entities
1 Entity mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
North Korean Hackers Hijack Axios to Push Malware
A suspected North Korean threat actor hijacked the popular open-source JavaScript library Axios on npm, pushing malicious versions that delivered a remote access trojan (RAT) for Windows, macOS and Linux. Security firm StepSecurity detected and helped stop the compromise after roughly three hours; Aikido warned that anyone who downloaded the affected package should assume compromise. Google’s Threat Intelligence Group attributed the attack to a suspected North Korean actor tracked as UNC1069, with John Hultquist (Google TIG) publicly commenting on the attribution. The attacker gained access by compromising a primary maintainer’s account, replacing the developer email and publishing legitimate-looking updates; the malware included self-deletion features to evade detection. The full scope and number of victims remain unclear.
Microsoft npm Packages Backdoored; AI Agents Trigger Credential Stealer
Seventy-three cryptographically signed Microsoft npm packages were compromised with a credential‑stealing worm called “Miasma,” derived from an open-source toolkit. The malware deploys a small (≈28 KB) payload that automatically harvests credentials from cloud providers (AWS, Azure, GCP), Kubernetes, many developer tool configs and password managers, and then spreads laterally through cloud infrastructure. The payload is triggered simply by opening a package inside AI coding agents and IDE integrations (examples named: Claude Code, Gemini CLI, Cursor, VS Code). Attackers used stolen Microsoft publisher credentials to publish malicious builds that carried valid SLSA provenance attestations, defeating provenance-only detection. The same Microsoft account had previously been compromised in May 2026 (durabletask Python SDK on PyPI), raising concerns about credential rotation and remediation.
Clinejection: AI Triage Bot Enables NPM Supply-Chain Attack
Clinejection is a chained supply‑chain exploit that turned an AI‑powered issue‑triage workflow into an attack vector, resulting in an unauthorized npm publication of a malicious package. The attack combined indirect prompt injection (via a crafted GitHub issue title), GitHub Actions cache poisoning, token exfiltration, and an npm publish that added a postinstall script to install a rogue AI agent called OpenClaw. Approximately 4,000 installs occurred during an eight‑hour window before the malicious package (cline@2.3.0) was yanked. The incident highlights gaps in workflows that give LLM agents write access and long‑lived automation tokens, and underscores defenses such as OIDC provenance, lifecycle‑script inspection, and local pre‑install SCA gates.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
