axios-native@1.16.3
Malicious code in axios-native (npm)
T1195.002 · Compromise Software Supply ChainT1036.005 · Match Legitimate Resource Name or Location
Analysis
Package name 'axios-native' is a combosquat of the popular 'axios' HTTP library. The npm maintainer name 'jasonsayman' typosquats the real axios maintainer 'jasonsaayman'. The package claims the real axios GitHub repository (github[.]com/axios/axios) as its own. It ships a verbatim copy of the axios v1.16.3 source code with no injected payload in this version — the impersonation is the attack vector, designed to trick developers into installing it as a trust-building step before a later version introduces malicious behaviour.
- analyzed by
- Leitwacht
- first seen
- Jul 17, 2026, 02:34 PM
- analyzed
- Jul 17, 2026, 02:36 PM
Related advisories
- @immobiliarelabs/backstage-plugin-gitlab-backend@3.0.3
- @immobiliarelabs/backstage-plugin-gitlab-backend@4.0.2
- theme-color-picker@2.0.28
- shadxino@1.0.7
- textify-kit@1.0.0
- solana-token-api@1.0.0
- openclaw-preview@2026.6.1
- chalk-plus-ts@1.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.