Popular JavaScript tool hijacked in short-lived but widespread attack
- rrelentless

- Aug 19
- 2 min read

Earlier this year, Malicious versions (1.14.1 and 0.30.4) of a widely used software component called Axios were briefly uploaded to npm, a popular platform used by developers to access code libraries. Axios is commonly used within websites and applications to manage data requests and is often included automatically during software builds.
Security researchers identified that these compromised versions contained hidden code designed to extract sensitive information from systems running Windows, macOS and Linux. Although the affected files were removed within a matter of hours, any system that downloaded thpopular-javascript-tool-hijacked-in-short-lived-but-widespread-attackem during that period may have been exposed.
The risk of automated software updates
This type of incident highlights the risks associated with reliance on third-party components and automated update processes. In many organisations, development tools and software libraries are updated without manual intervention, meaning malicious code can be introduced into internal systems without immediate detection.
Organisations should review how software components are managed and updated, particularly in critical environments. Development and build systems should be treated as sensitive, with appropriate access controls, monitoring and validation processes in place to reduce the risk of compromise.
Where there is potential exposure, organisations may wish to take precautionary steps such as resetting credentials, rotating access keys and reviewing activity logs for any unusual behaviour.
The role of cyber risk planning and insurance
Incidents like this demonstrate how quickly data exposure and operational disruption can occur, even without a targeted cyber-attack. Alongside robust technical controls and governance, it is important to recognise cyber insurance as part of a wider approach to managing cyber risk.
If you are a broker wanting to learn more about how rrelentless cyber insurance can support organisations in preparing for and responding to certain cyber incidents, you can find more information on our Cyber Insurance policy page.
For businesses interested in rrelentless insurance, please reach out to an insurance broker for advice.
rrelentless is one of many providers of cyber insurance, and that like most commercial insurance products, getting advice from an independent insurance intermediary is a great way to make setting up your insurance needs straightforward.


