Slow Fog flags malicious axios releases pulling in plain-crypto-js malware, exposing crypto developers to cross-platform RATs and stolen credentials via npm. BlockchainSlow Fog flags malicious axios releases pulling in plain-crypto-js malware, exposing crypto developers to cross-platform RATs and stolen credentials via npm. Blockchain

Slow Fog warns devs over malicious axios malware campaign

2026/03/31 22:30
Okuma süresi: 4 dk
Bu içerikle ilgili geri bildirim veya endişeleriniz için lütfen crypto.news@mexc.com üzerinden bizimle iletişime geçin.

Slow Fog flags malicious axios releases pulling in plain-crypto-js malware, exposing crypto developers to cross-platform RATs and stolen credentials via npm.

Summary
  • Slow Fog flags [email protected] and [email protected] as malicious after a maintainer account compromise.
  • The injected [email protected] package drops a cross-platform remote access trojan via postinstall scripts.
  • Developers using [email protected] are urged to rotate credentials and inspect hosts, as npm rolls back axios to 1.14.0.

Blockchain security firm Slow Fog has issued an urgent security reminder after newly published [email protected] and [email protected] releases pulled in a malicious dependency, [email protected], turning one of JavaScript’s most widely used HTTP clients into a supply chain weapon against crypto developers. Axios sees more than 80 million weekly downloads on npm, meaning even a short-lived compromise can ripple across wallet backends, trading bots, exchanges and DeFi infrastructure built on Node.js. In its advisory, Slow Fog warned that “users who installed [email protected] via npm install -g are potentially exposed,” recommending immediate credential rotation and thorough host-side investigation for signs of compromise.

The attack hinges on a fake cryptography package, [email protected], which is silently added as a new dependency and used solely to execute an obfuscated postinstall script that drops a cross-platform remote access trojan targeting Windows, macOS and Linux systems.

Security firm StepSecurity explained that “neither malicious version contains a single line of malicious code inside Axios itself,” and that instead “both inject a fake dependency, [email protected], whose only purpose is to run a postinstall script that deploys a cross-platform remote access trojan (RAT).” Socket’s research team noted that the malicious plain-crypto-js package was published just minutes before the compromised axios release, calling it a “coordinated supply chain attack” against the JavaScript ecosystem.

Axios maintainer account hijacked

According to StepSecurity, the malicious axios releases were pushed using stolen npm credentials belonging to primary maintainer “jasonsaayman,” allowing attackers to bypass the project’s usual GitHub-based release flow. “It’s a live supply chain compromise in [email protected], which newly depends on [email protected]—a package published hours earlier and identified as obfuscated malware that executes shell commands and erases traces,” security engineer Julian Harris wrote on LinkedIn. npm has now removed the malicious versions and reverted the axios resolution back to 1.14.0, but any environment that pulled 1.14.1 or 0.3.4 during the attack window remains at risk until secrets are rotated and systems are rebuilt.

The compromise echoes earlier npm incidents that directly targeted crypto users, including a 2025 campaign in which 18 popular packages like chalk and debug silently swapped wallet addresses to steal funds, prompting Ledger CTO Charles Guillemet to warn that “the affected packages have already been downloaded over 1 billion times.” Researchers have also documented npm malware stealing keys from Ethereum, XRP and Solana wallets, and SlowMist has estimated that crypto hacks and frauds — including backdoored packages and AI-assisted supply chain attacks — caused more than $2.3 billion in losses in the first half of 2025 alone. For now, Slow Fog’s advice is blunt: downgrade axios to 1.14.0, audit dependencies for any trace of [email protected] or openclaw, and assume that any credentials touched by those environments are compromised.

Previous software supply chain warnings

In a previous crypto.news story on JavaScript supply chain attacks, Ledger’s Guillemet warned that compromised npm packages with more than 2 billion weekly downloads posed a systemic risk to dApps and wallets built on Node.js. Another story detailed how North Korea’s Lazarus Group planted malicious npm packages to backdoor developer environments and target Solana and Exodus wallet users. A third crypto.news story on next-generation malware showed how backdoor supply chain attacks via npm and low-cost AI tools helped criminals remotely control over 4,200 developer machines and contributed to billions of dollars in crypto losses.

Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen crypto.news@mexc.com ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Stunning 96% Surge And 50% Plunge Define Volatile Market Session

Stunning 96% Surge And 50% Plunge Define Volatile Market Session

The post Stunning 96% Surge And 50% Plunge Define Volatile Market Session appeared on BitcoinEthereumNews.com. Crypto Gainers And Losers: Stunning 96% Surge And
Paylaş
BitcoinEthereumNews2026/04/03 09:20
Come Back To Me’ To Air At BIFF Before Global Release

Come Back To Me’ To Air At BIFF Before Global Release

The post Come Back To Me’ To Air At BIFF Before Global Release appeared on BitcoinEthereumNews.com. Kim Woo-sung performs onstage during “The Rose: Come Back to Me” premiere during the 2025 Tribeca Festival. Photo by Roy Rochlin/Getty Images for Tribeca Festival) Getty Images for Tribeca Festival The Rose: Come Back To Me will screen three times at the Busan International Film Festival and at additional film festivals worldwide, before its global theatrical release in 2026. The Korean alt-pop indie band known as The Rose is composed of Woosung, Dojoon, Hajoon, and Taegyeom. From their earliest days,busking in Hongdae, the band has captivated audiences with their distinctive genre-blending sound. Their first full-length album Heal sparked the global Heal Together World Tour, drawing over 90,000 fans and leading to high-profile festival appearances, including headlining the Bacardi Stage at Lollapalooza 2023. They reached a new milestone with their sophomore album Dual, which debuted on the Billboard 200. Building on this success, The Rose sold more than 150,000 tickets on their Dawn to Dusk Tour and delivered a show-stopping set at Coachella 2024. This year they went on a global tour, promoting their latest album WRLD alongside their documentary The Rose: Come Back to Me, which premiered at the Tribeca Film Festival in June 2025. “Knowing how dominant Korean culture is globally—from K-Pop Demon Hunters to Parasite—international audiences are all eager to go deeper and learn more” said Diane Quon and Sanjay M. Sharma on behalf of the producing team behind the popular Tribeca doc. “The Rose is as much a music doc as it is a coming-of-age story—about a group of friends finding their own way through the world. It’s a story of heartbreak and healing, conformity and individuality, and ultimately about the transformative power of music around the world.” Hajoon, Taegyeom, Kim Woo-sung and Dojoon perform onstage during “The Rose: Come Back to Me” premiere.. (Photo by Roy…
Paylaş
BitcoinEthereumNews2025/09/19 06:53
Hong Kong Monetary Authority cuts interest rates by 25 basis points

Hong Kong Monetary Authority cuts interest rates by 25 basis points

PANews reported on September 18 that according to Jinshi, the Hong Kong Monetary Authority lowered the benchmark interest rate by 25 basis points to 4.50%, and the Federal Reserve cut interest rates by 25 basis points overnight.
Paylaş
PANews2025/09/18 08:06

Trade GOLD, Share 1,000,000 USDT

Trade GOLD, Share 1,000,000 USDTTrade GOLD, Share 1,000,000 USDT

0 fees, up to 1,000x leverage, deep liquidity