Axios: npm Package Previously Compromised in Similar Supply Chain Attack
June 25, 2026
Axios is a popular npm package for making HTTP requests. In April 2026, it was compromised in a supply chain attack attributed to North Korean threat actors (UNC1069/Sapphire Sleet). The attack pattern—compromising a maintainer, inserting a malicious transitive dependency, and using an install-time dropper—closely mirrors the Mastra incident.