Axios Security Check

Checks for the March 2026 axios supply chain attack — two malicious npm versions (axios@1.14.1 and axios@0.30.4) that injected a RAT dropper via a fake dependency (plain-crypto-js@4.2.1). Use this skill whenever a user asks about axios security, whether their project is affected by the supply chain attack, how to check for plain-crypto-js, or wants to audit npm dependencies for compromise indicators. Also trigger when users mention "axios compromised", "axios malware", "axios RAT", "axios 1.14.1", "axios 0.30.4", or want to know if they need to rotate credentials after an npm install.

Install

openclaw skills install @vjumpkung/axios-security-check