axiosqqq@1.16.3
Malicious code in axiosqqq (npm)
Analysis
axiosqqq is a combosquatted copy of the popular axios HTTP library (the package name substitutes 'qqq' for part of 'axios'). The package itself contains an unmodified copy of axios's source code with no malicious code directly embedded. However, it declares a production dependency on @caspianph/storyteller, a known-malicious package. Installing axiosqqq pulls this dependency into node_modules, where its install-time lifecycle hooks execute — delivering the actual payload. Attackers use this pattern to evade static analysis: the combosquatted host package appears clean while the malicious dependency delivers the compromise.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 03:02 PM
- analyzed
- Jun 15, 2026, 03:03 PM
Related advisories
- flow-lending-sdk@9.9.9
- bodega-sdk@9.9.9
- surf-lending@9.9.9
- flowdefi@9.9.9
- flowcardano@9.9.9
- flow-lending@9.9.9
- ux-metrics-client-interaction-subscriber@45.0.0
- util-free-ports@3.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.