CRITICAL
Axios npm Supply Chain Incident Impacting @usebruno/cli
Published Apr 6, 2026
9.8
CRITICALCVSS 3.1
EPSS 0.32%
Description
Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised versions of the axios npm package, which introduced a hidden dependency deploying a cross-platform Remote Access Trojan (RAT). Users of @usebruno/cli who ran npm install between 00:21 UTC and ~03:30 UTC on March 31, 2026 may have been impacted. Upgrade to 3.2.1
Affected products
-
- Version < 3.2.1StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
@usebruno/cli
npm
Introduced 0 Fixed 3.2.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @usebruno/cli | 0 | 3.2.1 |
Remediation
No remediation recorded yet.
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-19354 Advisory
- https://github.com/advisories/GHSA-658g-p7jg-wx5g Advisory
- https://github.com/advisories/GHSA-fw8c-xr5c-95f9
- https://github.com/axios/axios/issues/10604 x_refsource_MISCIssue Tracking
- https://github.com/usebruno/bruno/pull/7632 x_refsource_MISCIssue TrackingPatch
- https://github.com/usebruno/bruno/security/advisories/GHSA-658g-p7jg-wx5g x_refsource_CONFIRMMitigationPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-34841
- https://www.aikido.dev/blog/axios-npm-compromised-maintainer-hijacked-rat x_refsource_MISCMitigationPress/Media Coverage
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-19354 | Advisory | |
| https://github.com/advisories/GHSA-658g-p7jg-wx5g | Advisory | |
| https://github.com/advisories/GHSA-fw8c-xr5c-95f9 | ||
| https://github.com/axios/axios/issues/10604 | x_refsource_MISCIssue Tracking | |
| https://github.com/usebruno/bruno/pull/7632 | x_refsource_MISCIssue TrackingPatch | |
| https://github.com/usebruno/bruno/security/advisories/GHSA-658g-p7jg-wx5g | x_refsource_CONFIRMMitigationPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-34841 | ||
| https://www.aikido.dev/blog/axios-npm-compromised-maintainer-hijacked-rat | x_refsource_MISCMitigationPress/Media Coverage |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 6, 2026
Updated Apr 8, 2026
Reserved Mar 30, 2026
Link CVE-2026-34841
CISA Vulnrichment
Updated Apr 6, 2026
ENISA EUVD
EUVD-2026-19354 GHSA-658G-P7JG-WX5G Assigner GitHub_M
Published Apr 6, 2026
Updated Apr 8, 2026
Exploited since n/a
Link EUVD-2026-19354