


Perceptive Security
SOC/SIEM Consultancy

Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised versions of the ax…
Published:
5 april 2026 om 22:00:00
Alert date:
6 april 2026 om 18:04:04
Source:
nvd.nist.gov
Supply Chain & Dependencies, Ransomware & Malware
Bruno IDE was affected by a supply chain attack targeting the axios npm package. The compromised package introduced a hidden dependency that deployed a cross-platform Remote Access Trojan (RAT). Users who installed @usebruno/cli between 00:21 UTC and 03:30 UTC on March 31, 2026 may have been compromised. The attack vector was through compromised versions of the axios npm package. Users are advised to upgrade to Bruno version 3.2.1 to mitigate the vulnerability.
Technical details
Mitigation steps:
Affected products:
Bruno IDE
axios npm package
@usebruno/cli
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-34841
https://github.com/axios/axios/issues/10604
https://github.com/usebruno/bruno/pull/7632
https://github.com/usebruno/bruno/security/advisories/GHSA-658g-p7jg-wx5g
https://www.aikido.dev/blog/axios-npm-compromised-maintainer-hijacked-rat
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
