Junglewise Threat Intelligence

CVE-2026-34841: Axios npm supply chain attack via @usebruno/cli

CVE-2026-34841 · Severity: low · CVSS 3.1 · Published 2026-04-02

Technologies: Axios. Vendors: npm, Axios.

Executive brief

@usebruno/cli is a command-line tool for the Bruno API testing platform. Between March 31 and April 1, 2026, users who ran npm install during a specific window received compromised versions of the axios dependency that deployed a remote access trojan (RAT). This allowed attackers to execute arbitrary code on developer machines, steal credentials and sensitive data, and maintain persistent access to affected systems.

Technical details

This is a supply chain attack targeting the axios npm package through dependency injection. Compromised versions (1.14.1 and 0.30.4) introduced a malicious postinstall script that executed a cross-platform RAT. The attack affected @usebruno/cli users who ran npm install between 00:21 UTC and ~03:30 UTC on March 31, 2026. The vulnerability is classified as improper integrity checking of downloaded code (CWE-494) and embedded malicious code (CWE-506). No user interaction or privileges are required—the exploit occurs automatically during package installation. Patches involve removing compromised axios versions from npm and pinning @usebruno/cli to safe versions (3.2.1+).

Affected products

  • Bruno @usebruno/cli < 3.2.1
  • Axios axios 1.14.1, 0.30.4 (compromised); affected versions distributed through @usebruno/cli < 3.2.0

Timeline

  • 2026-03-31: exploited: Supply chain attack active between 00:21 UTC and ~03:30 UTC on March 31, 2026
  • 2026-03-31: disclosed: Advisory published
  • 2026-04-02: patched: @usebruno/cli version 3.2.1 released; compromised axios versions removed from npm

References

Related threats