The Axios Hack
In March 2026, attackers took over the npm account behind axios, a JavaScript library that's pulled around 100 million times a week. Every step looked legitimate, right up until a prompt in a meeting asked the maintainer to install an update. Here's how it happened.

In March 2026, attackers took over the npm account behind axios, a JavaScript library that’s pulled around 100 million times a week. Here’s how it happened.
The attackers posed as the founder of a real company and approached axios’s lead maintainer, Jason Saayman. The exact company’s name has never been made public, but Saayman describes the attackers as having cloned both the company and its founder.
…the companys founders likeness as well as the company itself.
The attackers wanted to get in touch with Saayman and scheduled a meeting “to connect.” The record doesn’t say what for, but whatever the reason was, it seemed normal enough to accept.
The attackers invited Saayman into their Slack workspace. About two weeks passed between that first approach and the poisoned release.
The workspace was company-branded and reasonably named. It had channels resharing what Saayman took to be the company’s real LinkedIn posts, and profiles he took to be the team and a number of other open-source maintainers. The attackers then scheduled a call on Microsoft Teams, attended by what seemed to be a group of people.
At this point nothing seemed suspicious, but the deceptive act came in the middle of the call. Saayman received a prompt saying that his system was out of date. He installed the update, since it looked like it came from Teams. But it wasn’t, it was a cross-platform remote-access trojan.
Saayman had two-factor authentication switched on, but it didn’t make a difference.
and yes i did have 2fa enabled on my account.
He says he was told that once the trojan is on the machine, the attackers have full control of everything on it, and presumes they could do anything from there.
The attackers kept being patient even after gaining control of Saayman’s machine. They still didn’t publish immediately. First they released a small helper package and left it completely clean. Eighteen hours later they swapped in the malicious version, so that when axios started depending on it, it wouldn’t look brand new to anyone checking.
Then on March 31, they published two poisoned versions of axios from his account, and 89 seconds later the first computer was infected. About an hour after the malicious version went up, the developer community spotted the issue and filed bug reports. The attackers used the maintainer’s account to delete them, but an axios collaborator flagged the deletions and contacted npm, which pulled the packages.
The malicious package was live for about 3 hours, and Huntress observed at least 135 machines beaconing to the attackers during that window. The alarming part is that axios had no way to detect an unauthorized publish of its own. Detection depended on the community noticing.
Detection depended entirely on the community noticing.
Google’s threat intelligence group attributes this sophisticated phishing campaign to UNC1069, a North Korean operation it has tracked since 2018.
Every step in this social-engineering attack looked legitimate, right up until a prompt in a meeting asked to install an update. And detecting something like this is hard, because the channels it ran on are barely monitored for these types of attacks.
That gap is why we built Common Defense. We monitor for these types of attacks across Slack, Telegram, WhatsApp and email, and we alert the user if something suspicious is detected.
About Common Defense
Common Defense is an AI cyber lab built by security veterans and AI researchers, whose team has helped protect more than $300B in assets across 1,100+ security engagements. We help AI companies, fintechs, and crypto protocols secure the communication channels and operations that attackers target most.
