<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.appian.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>KB-2376 Information about the Axios Supply Chain Compromise</title><link>https://community.appian.com/support/w/kb/3791/kb-2376-information-about-the-axios-supply-chain-compromise</link><description /><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>KB-2376 Information about the Axios Supply Chain Compromise</title><link>https://community.appian.com/support/w/kb/3791/kb-2376-information-about-the-axios-supply-chain-compromise</link><pubDate>Wed, 01 Apr 2026 20:38:57 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:33a29212-f81a-4bc5-a233-f241e0302302</guid><dc:creator>Kaushal Patel</dc:creator><comments>https://community.appian.com/support/w/kb/3791/kb-2376-information-about-the-axios-supply-chain-compromise#comments</comments><description>Current Revision posted to Appian Knowledge Base by Kaushal Patel on 4/1/2026 8:38:57 PM&lt;br /&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;On 31 March 2026,&amp;nbsp; an Axios npm package that uses a JavaScript library to enable applications to make HTTP/S requests and is included as a dependency in millions of applications was compromised. Between ~00:21 and ~03:30 UTC, malicious versions (&lt;/span&gt;&lt;b&gt;axios@1.14.1 and axios@0.30.4&lt;/b&gt;&lt;span style="font-weight:400;"&gt;) were published using a compromised maintainer account.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian has investigated this vulnerability and affected services, and determined that it is &lt;/span&gt;&lt;b&gt;not impacted&lt;/b&gt;&lt;span style="font-weight:400;"&gt;, as no vulnerable versions of the packages are used in the Appian Cloud environment or any of Appian&amp;rsquo;s products. We will continue to monitor the situation and provide any updates as appropriate.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Supporting Documentation:&lt;/span&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/"&gt;&lt;span style="font-weight:400;"&gt;https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://www.mend.io/blog/poisoned-axios-npm-account-takeover-50-million-downloads-and-a-rat-that-vanishes-after-install/"&gt;&lt;span style="font-weight:400;"&gt;https://www.mend.io/blog/poisoned-axios-npm-account-takeover-50-million-downloads-and-a-rat-that-vanishes-after-install/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span&gt;Affected Versions&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;This article applies to all supported versions of Appian.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Last reviewed:&amp;nbsp;&lt;/span&gt;&lt;span&gt;April 1, 2026&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: Security&lt;/div&gt;
</description></item><item><title>KB-2376 Information about the Axios Supply Chain Compromise</title><link>https://community.appian.com/support/w/kb/3791/kb-2376-information-about-the-axios-supply-chain-compromise/revision/2</link><pubDate>Wed, 01 Apr 2026 20:34:59 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:33a29212-f81a-4bc5-a233-f241e0302302</guid><dc:creator>Kaushal Patel</dc:creator><comments>https://community.appian.com/support/w/kb/3791/kb-2376-information-about-the-axios-supply-chain-compromise#comments</comments><description>Revision 2 posted to Appian Knowledge Base by Kaushal Patel on 4/1/2026 8:34:59 PM&lt;br /&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;On 31 March 2026,&amp;nbsp; an Axios npm package that uses a JavaScript library to enable applications to make HTTP/S requests and is included as a dependency in millions of applications was compromised. Between ~00:21 and ~03:30 UTC, malicious versions (&lt;/span&gt;&lt;b&gt;axios@1.14.1 and axios@0.30.4&lt;/b&gt;&lt;span style="font-weight:400;"&gt;) were published using a compromised maintainer account.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian has investigated this vulnerability and affected services, and determined that it is &lt;/span&gt;&lt;b&gt;not impacted&lt;/b&gt;&lt;span style="font-weight:400;"&gt;, as no vulnerable versions of the packages are used in the Appian Cloud environment or any of Appian&amp;rsquo;s products. We will continue to monitor the situation and provide any updates as appropriate.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Supporting Documentation:&lt;/span&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/"&gt;&lt;span style="font-weight:400;"&gt;https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://www.mend.io/blog/poisoned-axios-npm-account-takeover-50-million-downloads-and-a-rat-that-vanishes-after-install/"&gt;&lt;span style="font-weight:400;"&gt;https://www.mend.io/blog/poisoned-axios-npm-account-takeover-50-million-downloads-and-a-rat-that-vanishes-after-install/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span&gt;Affected Versions&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;This article applies to all supported versions of Appian.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Last reviewed:&amp;nbsp;&lt;/span&gt;&lt;span&gt;April 1, 2026&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item><item><title>KB-XXXX Information about the Axios Supply Chain Compromise</title><link>https://community.appian.com/support/w/kb/3791/kb-2376-information-about-the-axios-supply-chain-compromise/revision/1</link><pubDate>Wed, 01 Apr 2026 20:31:01 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:33a29212-f81a-4bc5-a233-f241e0302302</guid><dc:creator>Kaushal Patel</dc:creator><comments>https://community.appian.com/support/w/kb/3791/kb-2376-information-about-the-axios-supply-chain-compromise#comments</comments><description>Revision 1 posted to Appian Knowledge Base by Kaushal Patel on 4/1/2026 8:31:01 PM&lt;br /&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;On 31 March 2026,&amp;nbsp; an Axios npm package that uses a JavaScript library to enable applications to make HTTP/S requests and is included as a dependency in millions of applications was compromised. Between ~00:21 and ~03:30 UTC, malicious versions (&lt;/span&gt;&lt;b&gt;axios@1.14.1 and axios@0.30.4&lt;/b&gt;&lt;span style="font-weight:400;"&gt;) were published using a compromised maintainer account.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian has investigated this vulnerability and affected services, and determined that it is &lt;/span&gt;&lt;b&gt;not impacted&lt;/b&gt;&lt;span style="font-weight:400;"&gt;, as no vulnerable versions of the packages are used in the Appian Cloud environment or any of Appian&amp;rsquo;s products. We will continue to monitor the situation and provide any updates as appropriate.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Supporting Documentation:&lt;/span&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/"&gt;&lt;span style="font-weight:400;"&gt;https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://www.mend.io/blog/poisoned-axios-npm-account-takeover-50-million-downloads-and-a-rat-that-vanishes-after-install/"&gt;&lt;span style="font-weight:400;"&gt;https://www.mend.io/blog/poisoned-axios-npm-account-takeover-50-million-downloads-and-a-rat-that-vanishes-after-install/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span&gt;Affected Versions&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;This article applies to all supported versions of Appian.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Last reviewed:&amp;nbsp;&lt;/span&gt;&lt;span&gt;April 1, 2026&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item></channel></rss>