top of page
perceptive_background_267k.jpg

Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised versions of the ax…

Published:

5 April 2026 at 22:00:00

Alert date:

6 April 2026 at 18:04:04

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Ransomware & Malware

Bruno IDE was affected by a supply chain attack targeting the axios npm package. The compromised package introduced a hidden dependency that deployed a cross-platform Remote Access Trojan (RAT). Users who installed @usebruno/cli between 00:21 UTC and 03:30 UTC on March 31, 2026 may have been compromised. The attack vector was through compromised versions of the axios npm package. Users are advised to upgrade to Bruno version 3.2.1 to mitigate the vulnerability.

Technical details

Mitigation steps:

Affected products:

Bruno IDE
axios npm package
@usebruno/cli

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page