This package has dated incident reports relevant to its trust history. Check the affected releases and the response before drawing conclusions about its current version.
StepSecurity traced two malicious Axios releases to compromised publishing credentials. A newly added dependency delivered the payload; the affected releases were subsequently removed from npm.
Build provenance — the latest release, 1.20.0, carries a signed provenance attestation. Source: the registry.
Publishers on the registry — 1. Source: the registry.
Security policy — published. Source: the repository.
OpenSSF Scorecard — 8 / 10 on 2026-08-17. Source: OpenSSF, via deps.dev. A third party's view of security practice, not part of the health score.
Third-party facts checked yesterday; registry facts on every crawl.
State history 1
When
Change
2026-09-05
first verdict: active
Supply-chain history 1
account hijacked2026-031.14.1, 0.30.4
The lead maintainer was socially engineered through a fake workspace and call into installing a trojan; the attacker then published two versions that added a never-imported dependency whose post-install script dropped a remote-access tool.
npm removed the packages about three hours later and revoked tokens; the maintainer published a post-mortem.
Source: Datadog Security Labs analysis and the maintainer’s post-mortem, 31 March 2026. History, not a warning about today — the verdict above is about maintenance now.
Badge
Drop this in your README. It re-renders itself as the verdict changes.