Axios 1.14.1 compromised with malware, targets AI-assisted development workflows

Supply chain attack targets axios package
A supply chain attack has compromised axios version 1.14.1, which silently pulls in [email protected] as a dependency. This package is an obfuscated RAT (Remote Access Trojan) dropper. NPM has pulled the malicious version, but developers who installed it during the window of vulnerability may be infected.
AI-assisted development workflows at risk
The attack specifically targets developers using AI coding assistants like Claude. The source notes that with AI coding, developers often let the AI handle package installation without checking package.json diffs or auditing what dependencies are being pulled in. Attackers are exploiting this trust in automated workflows where developers scaffold projects and run installs without manual verification.
Immediate detection and remediation steps
Run these commands to check for infection:
# Check your lockfile
grep -r "plain-crypto-js" package-lock.json
grep -r "[email protected]" package-lock.json
Check for persistence artifacts
ls -la /library/caches/com.apple.act.mond # macOS
ls /tmp/ld* # Linux
If you find the malicious package:
- Roll back to [email protected] immediately
- Rotate all keys and credentials (AWS credentials, API keys, etc.)
- Audit all lockfiles in your projects
Preventive measures
The source recommends pinning versions and manually auditing what dependencies AI assistants are pulling in. Developers should slow down on automated installs and actually read what packages are being added to their projects.
📖 Read the full source: r/ClaudeAI
👀 See Also

Critical Cowork Bug: AI Agent Deleted Files Without User Approval
A critical bug in Claude's Cowork mode allowed the AI to execute destructive actions without user consent. The ExitPlanMode tool falsely reported user approval, triggering an autonomous agent that deleted 12 files from a React/TypeScript codebase.

Testing Uncensored Qwen 3.5 35B Models for Cybersecurity Questions
A cybersecurity professional tested three uncensored Qwen 3.5 35B models on hacking and security bypass questions, finding significant differences in response quality compared to the original censored model. The uncensored models consistently provided answers where the original model refused or gave incomplete responses.

Claude Code Worm 'Hades' Steals Credentials Via AI Configs & Python Startup Hooks
The active Claude Code attack (UNC6780) has evolved into 'Hades' — a worm that spreads through Python, passes AI scanners, and plants config hooks in Claude, Cursor, Copilot, and Gemini to steal secrets.

Microsoft's Open Source Tools Hacked: Password-Stealing Malware Hits AI Developer Repos
Hackers injected password-stealing malware into at least 70 Microsoft GitHub repos, targeting AI developers using Claude Code, Gemini CLI, and VS Code. This is a re-compromise of the earlier Durable Task breach.