---
id: "2038807290422370479"
requested_id: "2038807290422370479"
status: ok
level: 2
user: "feross"
name: "Feross"
created_at: "2026-03-31T02:35:11.000Z"
in_reply_to: null
quoted: null
source: tweet-result
url: "https://x.com/feross/status/2038807290422370479"
via:
  - level2: "2039130814479204630"
---

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.

The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise.

This is textbook supply chain installer malware. axios
