Skip to main content
Microsoft Security

Photo of developers discussing with the hexagon and the supply chain attack icon in overlay

Mitigating the Axios npm supply chain compromise

On March 31, 2026, the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages for version updates to download from command and control (C2) that Microsoft Threat Intelligence has attributed to the North Korean state actor Sapphire Sleet.

Threat intelligence

Stay ahead of threats

Get expert insights, threat intelligence, and the latest cybersecurity reports from Security Insider.

AI and machine learning

Modernize your security operations center

Confidently secure your multicloud, multiplatform environment with Microsoft Sentinel – a cloud-native security information and event management (SIEM) solution.

Latest posts