LWA-2026-5431 MAL-2026-4493 ↗ confirmed malware

axiosqqq@1.16.3

Malicious code in axiosqqq (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

axiosqqq is a combosquatted copy of the popular axios HTTP library (the package name substitutes 'qqq' for part of 'axios'). The package itself contains an unmodified copy of axios's source code with no malicious code directly embedded. However, it declares a production dependency on @caspianph/storyteller, a known-malicious package. Installing axiosqqq pulls this dependency into node_modules, where its install-time lifecycle hooks execute — delivering the actual payload. Attackers use this pattern to evade static analysis: the combosquatted host package appears clean while the malicious dependency delivers the compromise.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 03:02 PM
analyzed
Jun 15, 2026, 03:03 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.