Skip to main content
← All Articles

Tag

#Axios

12 articles

Advertisement

HIGH
Vulnerabilities

CVE-2026-40175: Siemens gWAP RCE via Axios Prototype Pollution

Siemens gWAP is vulnerable to RCE via CVE-2026-40175, a prototype pollution flaw in the Axios HTTP client library. Update to v3.1.1 or later.

Runtime Rebel Intel
4 min read · May 14, 2026
HIGH
Supply Chain

Axios npm Supply Chain Attack: Malicious Payloads and Mitigation

Axios npm versions 1.14.1 and 0.30.4 compromised via a malicious dependency injecting remote access trojans. Learn how to detect and remediate this threat.

Runtime Rebel Intel
4 min read · Apr 21, 2026
OpenAI Revokes macOS App Certificate Following Supply Chain Attack
HIGH
Supply Chain

OpenAI Revokes macOS App Certificate Following Supply Chain Attack

OpenAI revokes its macOS app signing certificate after a GitHub Actions workflow downloaded a malicious Axios library version during a supply chain incident.

Runtime Rebel Intel
3 min read · Apr 13, 2026
Axios Attack: Industrialized Social Engineering on NPM Maintainers
HIGH
Supply Chain

Axios Attack: Industrialized Social Engineering on NPM Maintainers

An analysis of the Axios NPM package attack reveals advanced, scaled social engineering campaigns targeting open-source maintainers, elevating supply chain risk.

Runtime Rebel Intel
4 min read · Apr 7, 2026
HIGH
Supply Chain

Axios npm Hijack Attempt: Detecting Social Engineering Tactics

North Korean threat actors targeted an Axios maintainer with a fake Microsoft Teams fix, highlighting critical risks to open-source supply chains.

Runtime Rebel Intel
3 min read · Apr 5, 2026
UNC1069 Social Engineering Leads to Axios npm Supply Chain Compromise
HIGH
Supply Chain

UNC1069 Social Engineering Leads to Axios npm Supply Chain Compromise

Runtime Rebel details how North Korean threat actor UNC1069 leveraged targeted social engineering against an Axios npm package maintainer, leading to a critical supply…

Runtime Rebel Intel
4 min read · Apr 3, 2026

Advertisement

HIGH
Supply Chain

Axios NPM Supply Chain Attack Bypasses GitHub Actions CI/CD

A sophisticated supply chain attack targeted the Axios NPM package, leveraging a compromised token to bypass GitHub Actions CI/CD and deploy malicious versions.

Runtime Rebel Intel
4 min read · Apr 1, 2026
Axios npm Supply Chain Attack Attributed to North Korea's UNC1069
HIGH
Supply Chain

Axios npm Supply Chain Attack Attributed to North Korea's UNC1069

Google Threat Intelligence attributes a major Axios npm supply chain attack to North Korean group UNC1069, emphasizing risks to developer environments.

Runtime Rebel Intel
4 min read · Apr 1, 2026
HIGH
Supply Chain

UNC1069 Leverages Axios NPM Supply Chain to Deploy WAVESHAPER.V2

North Korea-nexus UNC1069 compromised widely used Axios NPM package (v1.14.1, 0.30.4) by injecting plain-crypto-js to deploy WAVESHAPER.V2 backdoor across multiple OS.

Runtime Rebel Intel
8 min read · Apr 1, 2026
Axios NPM Compromise: Supply Chain Threat Analysis
HIGH
Supply Chain

Axios NPM Compromise: Supply Chain Threat Analysis

Analysis of the Axios NPM package compromise, a potential supply chain attack impacting JavaScript HTTP client library users, possibly by North Korean threat actors.

Runtime Rebel Intel
5 min read · Apr 1, 2026
HIGH
Supply Chain

Axios npm Package Hijacked: Cross-Platform Malware Distribution

Analysis of the Axios npm package hijack distributing remote access trojans to Linux, Windows, and macOS systems. Learn to protect your software supply chain.

Runtime Rebel Intel
5 min read · Mar 31, 2026
Axios Supply Chain Attack: RAT Found in Versions 1.14.1 and 0.30.4
HIGH
Supply Chain

Axios Supply Chain Attack: RAT Found in Versions 1.14.1 and 0.30.4

Malicious Axios versions 1.14.1 and 0.30.4 inject a cross-platform RAT via a fake dependency. Identify and remediate this npm supply chain threat now.

Runtime Rebel Intel
4 min read · Mar 31, 2026