On March 31, 2026, Microsoft Threat Intelligence flagged versions 1.14.1 and 0.30.4 of the Axios package on npm as malicious. Both included a fake dependency used to download payloads from control-and-command domains associated with Sapphire Sleet, a state-sponsored North Korean threat actor.
The case is particularly sensitive because Axios is a widely utilized component in JavaScript applications, both on the client and server sides. This immediately expands the attack surface, making rapid response an operational necessity: identifying affected installations, containing the execution of the compromised package, and rotating potentially exposed secrets.