NPM Compromise via Axios Backdoor: Impact on AI Coding Agents

NPM Security Incident: Axios Package Compromise
A significant security breach occurred on March 31, 2026, when npm was temporarily compromised. A DPRK-linked threat actor stole credentials from an Axios maintainer and published two malicious package versions.
Attack Details
- Compromised versions: Axios 1.14.1 and 0.30.4
- Attack window: 3 hours
- Safe versions: 1.14.0 and 0.30.3
- Attack vector: The attacker published backdoored versions that injected a malicious dependency
- Malware behavior: The dependency ran a postinstall hook that downloaded a platform-specific RAT (remote access trojan)
- RAT capabilities: Established C2 beacons, harvested credentials, and self-erased after installation
Impact and Scope
Axios receives 400 million monthly downloads with 174,000 direct dependents, creating a massive blast radius. The attack was particularly devastating for AI coding agents including Claude Code, Cursor, and Copilot. These tools run npm install autonomously without human review, and the malware detached from the process before the command returned — making it completely invisible to output monitoring.
Thousands of developer machines were compromised within hours before the packages were removed from npm. If you installed any packages via npm during the attack window, you should consider the entire machine compromised.
Immediate Actions
- Check if you installed packages during the 3-hour window on March 31, 2026
- Verify you're using Axios versions 1.14.0 or 0.30.3 (not 1.14.1 or 0.30.4)
- Assume machines that installed compromised packages are fully compromised
- Review security monitoring for AI coding agent environments that automate npm installs
📖 Read the full source: r/openclaw
👀 See Also

Declawed: An Advanced Community-Driven Malware Scanner for ClawHub SKILL.md Files
Declawed is a security tool for scanning SKILL.md files on ClawHub, detecting prompt injection, malicious content, and info stealers, utilizing community-driven rulesets.

Claude implements identity verification for certain use cases
Anthropic is rolling out identity verification for Claude through Persona Identities, requiring government-issued photo IDs and live selfies. The verification process takes under five minutes and is used to prevent abuse and comply with legal obligations.

Critical OpenClaw Security Vulnerabilities Patched in 2026.3.28
OpenClaw version 2026.3.28 patches 8 critical security vulnerabilities found by Ant AI Security Lab, including sandbox bypass, privilege escalation, and SSRF risks. Users on versions ≤2026.3.24 should update immediately.

Malwar: A Vulnerability Scanner for SKILL.md Files Built with Claude Code
A developer has released Malwar, a free tool that scans SKILL.md files for malicious instructions using a 4-layer pipeline including a rule engine, URL crawler, LLM analysis, and threat intel. The tool was built entirely with Claude Code after the developer found concerning patterns like Base64 blobs and instructions to pipe curl output to bash in existing skills.