MAL-2026-4493
Dashboard / Malicious Package / MAL-2026-4493
MAL-2026-4493
Summary: Malicious code in axiosqqq (npm)
Details: Source: amazon-inspector (a9cf5bc7a896b21f9af923c60b9283758bf46d4fb279f752a42bae43bb6006aa) Package name `axiosqqq` is a 3-character-suffix typosquat of `axios` and ships axios's verbatim source, README, and CHANGELOG to impersonate the legitimate package. The only material divergence from upstream axios is an added runtime dependency in package.json: `"@caspianph/storyteller": "^1.0.0"`. No file in the tarball imports or references this dependency, so it serves no functional purpose in the package; its only effect is that `npm install axiosqqq` resolves and installs `@caspianph/storyteller`, whose lifecycle hooks and main module will execute in the installer's environment. This is the namespace-abuse / smuggled-transitive-dependency pattern: the lure package mimics a top-tier registry name to get installed, and the actual payload is the unrelated scoped package pulled in transitively. The static C2/POST/ping pattern matches fire on the bundled axios.cjs and reflect axios's normal HTTP-client surface (POST, fetch, ping helpers) rather than added exfiltration code — the typosquat's harm is structural, via the injected dependency, not via modifications to the axios bundle itself.
References: https://www.npmjs.com/package/axiosqqq/v/1.16.2, https://www.npmjs.com/package/axiosqqq/v/1.16.3, https://www.npmjs.com/package/axiosqqq/v/1.16.9, https://www.npmjs.com/package/axiosqqq/v/1.16.13
Affected packages
Package
Name: axiosqqq
Purl: pkg:npm/axiosqqq
Affected ranges
Type: N/A
Events:
