Axios NPM Supply Chain Compromise: Malicious Packages Deliver Remote Access Trojan - PDF-XChange Unaffected
Security Bulletin Apr 3, 2026
On March 31, 2026, attackers compromised the official Axios package on the Node Package Manager (npm) registry. Axios is one of the most widely used open-source libraries for making web requests, with over a hundred million downloads per week. It's embedded in web applications, mobile apps, backend services, and automated build pipelines across virtually every industry.
https://www.sans.org/blog/axios-npm-supply-chain-compromise-malicious-packages-remote-access-trojan
PDF-XChange uses Axios libraries on our website. However, we at PDF-XChange had not yet completed our review and testing of the latest release and therefore were yet to either approve or implement the release that was compromised.
We have thoroughly reviewed our servers, and no malware was detected. Consequently, we are pleased to confirm that our systems were completely unaffected.
Best regards,
PDF-XChange Co. Security Team
