Executive brief
@usebruno/cli is a command-line tool for the Bruno API testing platform. Between March 31 and April 1, 2026, users who ran npm install during a specific window received compromised versions of the axios dependency that deployed a remote access trojan (RAT). This allowed attackers to execute arbitrary code on developer machines, steal credentials and sensitive data, and maintain persistent access to affected systems.
Technical details
This is a supply chain attack targeting the axios npm package through dependency injection. Compromised versions (1.14.1 and 0.30.4) introduced a malicious postinstall script that executed a cross-platform RAT. The attack affected @usebruno/cli users who ran npm install between 00:21 UTC and ~03:30 UTC on March 31, 2026. The vulnerability is classified as improper integrity checking of downloaded code (CWE-494) and embedded malicious code (CWE-506). No user interaction or privileges are required—the exploit occurs automatically during package installation. Patches involve removing compromised axios versions from npm and pinning @usebruno/cli to safe versions (3.2.1+).
Affected products
- Bruno @usebruno/cli < 3.2.1
- Axios axios 1.14.1, 0.30.4 (compromised); affected versions distributed through @usebruno/cli < 3.2.0
Timeline
- 2026-03-31: exploited: Supply chain attack active between 00:21 UTC and ~03:30 UTC on March 31, 2026
- 2026-03-31: disclosed: Advisory published
- 2026-04-02: patched: @usebruno/cli version 3.2.1 released; compromised axios versions removed from npm