workflow automation

A stolen npm token turned axios into a backdoor for three hours.

A recent security breach has exposed a significant vulnerability within the npm ecosystem, impacting the widely used Axios library.

4 min readVentureBeat
A stolen npm token turned axios into a backdoor for three hours.

The axios compromise is the clearest possible proof that the security community has been optimizing for the wrong threat model. Three major npm supply chain attacks in seven months, three stolen maintainer credentials, and every single defensive layer that got deployed after the first two incidents failed to stop the third. The attacker didn't outsmart OIDC or SLSA or any of the modern controls that were supposed to make this class of attack obsolete. They simply found a legacy token that npm's own authentication hierarchy preferred over the newer, safer mechanism, and that was the whole ballgame. The lesson is uncomfortable but unavoidable: you can build a fortress around the front door and leave the back door wide open, and everyone will still walk through the back door.

For organizations running Node.js, this is not a story about a single library having a bad day. It is a story about the structural fragility of the entire open source supply chain. Axios sits in roughly 80% of cloud and code environments. A malicious package published under that name gets pulled into CI/CD pipelines, serverless functions, and React front-ends automatically, often without a human ever reviewing what changed. The three-hour exposure window during Asia-Pacific peak hours means any pipeline that ran an install overnight could have ingested the RAT. The first infections were detected 89 seconds after the malicious package went live, and it still took three hours to remove. That is the real timeline to internalize: detection was nearly instant, but remediation took the better part of an afternoon. Your security tools can flag a problem in seconds, but your ability to respond is still measured in hours.

The practical response is not to abandon open source or to demand that every dependency be rewritten from scratch. It is to assume that maintainer credentials will be stolen, because they will be, and to build your controls around that assumption rather than around the hope that it won't happen. That means enforcing lockfile-only installs with `npm ci --ignore-scripts` in every build. It means auditing your own publishing workflows for legacy tokens that coexist with OIDC, because the axios maintainer did not know his token was still active either. It means treating any package that suddenly appears with a postinstall script as an immediate red flag, regardless of how legitimate the package name looks. And it means checking your lockfiles and CI logs right now for axios@1.14.1, axios@0.30.4, or plain-crypto-js, because the window for catching this before it spreads is already closing.

The uncomfortable truth is that the industry has known the answer for years, and the answer keeps getting ignored because it is inconvenient. Mandatory provenance attestation would have caught this attack before it reached the registry. Mandatory multi-party signing would have required a second maintainer to approve the release. Disabling classic tokens entirely when OIDC is enabled would have removed the attack vector altogether. None of these are new ideas. They are all on the roadmap, and they will all be implemented the day after the next major compromise, and then the cycle will repeat. The only question that matters is whether your organization is going to wait for that cycle to play out again, or whether you are going to treat this incident as the warning it is. Check your lockfiles, rotate your credentials, and assume that your supply chain is already compromised. That is not pessimism. That is the only realistic posture left.

From VentureBeat

Attackers stole a long-lived npm access token belonging to the lead maintainer of axios, the most popular HTTP client library in JavaScript, and used it to publish two poisoned versions that install a cross-platform remote access trojan. The malicious releases target macOS, Windows, and Linux. They were live on the npm registry for roughly three hours before removal.

Read the original at VentureBeat