TL;DR
On March 30–31, 2026, axios versions 1.14.1 and 0.30.4 were compromised on npm with a malicious dependency that drops a remote access trojan (RAT) on infected machines. Both versions have been unpublished. The safe version is 1.14.0. If you installed axios@1.14.1 or 0.30.4, treat the machine as compromised and rotate all credentials immediately.
Try Apidog today
What happened
axios is one of the most widely used HTTP clients in the JavaScript ecosystem, with roughly 100 million weekly npm downloads. It is used in frontend apps, backend Node.js services, internal tools, and enterprise systems.







