NPM Compromise via Axios Backdoor: Impact on AI Coding Agents

NPM Security Incident: Axios Package Compromise
A significant security breach occurred on March 31, 2026, when npm was temporarily compromised. A DPRK-linked threat actor stole credentials from an Axios maintainer and published two malicious package versions.
Attack Details
- Compromised versions: Axios 1.14.1 and 0.30.4
- Attack window: 3 hours
- Safe versions: 1.14.0 and 0.30.3
- Attack vector: The attacker published backdoored versions that injected a malicious dependency
- Malware behavior: The dependency ran a postinstall hook that downloaded a platform-specific RAT (remote access trojan)
- RAT capabilities: Established C2 beacons, harvested credentials, and self-erased after installation
Impact and Scope
Axios receives 400 million monthly downloads with 174,000 direct dependents, creating a massive blast radius. The attack was particularly devastating for AI coding agents including Claude Code, Cursor, and Copilot. These tools run npm install autonomously without human review, and the malware detached from the process before the command returned — making it completely invisible to output monitoring.
Thousands of developer machines were compromised within hours before the packages were removed from npm. If you installed any packages via npm during the attack window, you should consider the entire machine compromised.
Immediate Actions
- Check if you installed packages during the 3-hour window on March 31, 2026
- Verify you're using Axios versions 1.14.0 or 0.30.3 (not 1.14.1 or 0.30.4)
- Assume machines that installed compromised packages are fully compromised
- Review security monitoring for AI coding agent environments that automate npm installs
📖 Read the full source: r/openclaw
👀 See Also

OpenObscure: Open-Source On-Device Privacy Firewall for AI Agents
OpenObscure is an open-source, on-device privacy firewall that sits between AI agents and LLM providers. It uses FF1 Format-Preserving Encryption with AES-256 to encrypt PII values before requests leave your device, maintaining data structure while protecting privacy.

Claude Code source code reportedly leaked via NPM map file
A tweet reports that Claude Code's source code has been leaked through a map file in their NPM registry. The HN discussion has 93 points and 35 comments.

Claude Code source map leak reveals minified JavaScript was already public on npm
A source map file accidentally included in version 2.1.88 of the @anthropic-ai/claude-code npm package revealed internal developer comments, but the actual 13MB cli.js file containing 148,000+ plaintext strings has been publicly accessible on npm since launch.

MCP Server CVE Exposure Mapping and Public API Released
Researchers have mapped CVE exposure across thousands of MCP servers and built a public API for querying dependency vulnerabilities. The API allows searching by repo/name, filtering by severity, and sorting by CVE count or recency.