Darktrace: 100M-Weekly Axios Downloads Hijacked as Cloud Top Attack Target
For cybersecurity teams, the H1 2026 shift to identity-based attacks in cloud and SaaS environments means traditional defenses are failing. Attackers now inherit trust through compromised accounts, libraries, and admin tools, expanding the breach surface exponentially.
Beat this week
Last 7 days · Threat Intelligence
Impact 5.9/10 (+0.1 vs prior). Counts are stories in our record, not a market forecast.
Open the change reportCoverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 12 percentage points.
This story sits in Threat Intelligence — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.
Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.
Cybersecurity briefing
Key takeaways
- For cybersecurity teams, the H1 2026 shift to identity-based attacks in cloud and SaaS environments means traditional defenses are failing.
- Attackers now inherit trust through compromised accounts, libraries, and admin tools, expanding the breach surface exponentially.
- James Coker
- It Security News
In this briefing
Mentioned
Key Intelligence
Key Facts
- 1Darktrace report reveals cloud and SaaS environments are now the top targets for cyber-threat actors in H1 2026.
- 2Attackers moved beyond credential theft to compromise email authentication, cloud entitlements, AI gateways, remote admin tools, and non-human identities.
- 3A single compromised SaaS account led to malicious email rule changes, phishing attacks, and lateral network movement, evading detection by appearing innocuous in isolation.
- 4In April 2026, the Axios JavaScript library, downloaded over 100 million times per week, was hijacked to distribute remote access trojans (RATs).
- 5Legitimate blockchain infrastructure was abused to spread infostealers such as AMOS and Phexia, targeting users with limited security resources.
- 6Trust is the new attack surface, as attackers inherit legitimate access through compromised identities rather than bypassing controls.
Axios library hijacked to distribute RATs in April 2026
Increasingly, attackers do not need to bypass trust controls in these environments; they inherit them through compromised identities, delegated access, and legitimate administration tools.
H1 2026 trends
Analysis
Cybersecurity professionals have long prepared for malware and vulnerability exploits, but Darktrace’s new report makes a stark case: the battlefield has moved to the cloud, and your biggest blind spot is trust. In the first half of 2026, attackers didn’t just steal credentials—they turned AI gateways, CI/CD pipelines, and even a ubiquitous JavaScript library into attack highways, leaving signature-based tools blind to the intrusion.
The cybersecurity landscape has undergone a significant transformation in the first half of 2026, with cloud and SaaS environments emerging as the primary targets for sophisticated threat actors. According to a new report by Darktrace, attackers have completed a pivot away from traditional malware and vulnerability exploitation toward a strategy centered on compromising identities. While 2025 saw a heavy focus on stealing account credentials, H1 2026 has witnessed an alarming expansion into email authentication protocols, cloud entitlement abuse, software supply chain corruption, AI gateway infiltration, remote administration tooling, and non-human identities. This shift effectively makes 'trust' the new attack surface, as malicious actors inherit established permissions and legitimate access rather than forcibly bypassing them.
Similarly, Darktrace observed the abuse of legitimate blockchain infrastructure to disseminate infostealers like AMOS and Phexia, preying on users who often lack robust security measures.
The implications are profound. In one illustrative case highlighted by Darktrace, a single compromised SaaS account triggered a cascade of malicious activity across email, SaaS applications, and network layers—including inbox rule modifications and internal phishing campaigns. Crucially, none of these individual indicators were severe enough to trip traditional detection mechanisms on their own; only when correlated did they reveal a clear intrusion. This underscores a fundamental challenge for defenders: as attack patterns grow more subtle and span multiple platforms, security teams must evolve from isolated alerting to holistic behavioral analysis.
The threat multiplies further when attackers target the software supply chain. In April 2026, malicious actors hijacked Axios, a widely used JavaScript library downloaded over 100 million times per week, to distribute remote access trojans (RATs). Because Axios is deeply embedded in countless developer environments and CI/CD pipelines, the breach not only infected end-user machines but gave attackers a foothold in the software development lifecycle itself. Similarly, Darktrace observed the abuse of legitimate blockchain infrastructure to disseminate infostealers like AMOS and Phexia, preying on users who often lack robust security measures. These tactics demonstrate a disturbingly efficient model: by compromising a single trusted node—be it a library, a SaaS account, or a blockchain service—attackers can reach an exponentially larger victim base with minimal effort.
Behind these developments lies a broader industrial trend: the rapid adoption of cloud services has expanded the organizational attack perimeter far beyond the traditional network boundary. Businesses now rely on a web of interconnected SaaS applications, APIs, and third-party integrations, each representing a potential trust relationship that can be exploited. Darktrace's observation that attackers no longer need to bypass trust controls but instead inherit them through compromised identities or delegated access is a sobering reminder that the very mechanisms designed to enable seamless collaboration—single sign-on, OAuth tokens, service accounts—are now prime vectors for intrusion.
What to Watch
For security practitioners, the report serves as a call to action on several fronts. First, identity and access management (IAM) must be elevated from an administrative function to a core security discipline, with continuous monitoring of privilege escalations and anomalous behavior. Second, software supply chain security demands uncompromising rigor: vetting library dependencies, implementing code-signing, and adopting zero-trust principles even within trusted pipelines. Third, AI-driven anomaly detection becomes essential, as legacy rule-based systems fail to spot the subtle, multi-stage attacks that now define the threat landscape.
Looking ahead, the trajectory is unlikely to reverse. As organizations migrate more critical operations to the cloud and increasingly rely on AI gateways and automated workflows, the opportunities for identity-based attacks will only multiply. Non-human identities—service accounts, bots, and machine-to-machine interactions—represent a particularly fast-growing and under-protected segment. Darktrace's findings indicate that the industry must fundamentally rethink trust architectures, moving from implicit to explicit verification and embracing real-time, context-aware security models. The lesson of H1 2026 is clear: in a world where trust is the attack surface, the only sustainable defense is to assume no identity, no library, and no service is inherently trustworthy.
Timeline
Timeline
Shift to Identity-Based Attacks Begins
Attackers begin shifting away from malware and vulnerability exploitation toward compromising user account credentials.
H1 2026 Attack Surface Expands
Attacks extend to email authentication, cloud entitlements, software supply chains, AI gateways, remote admin tools, and non-human identities.
Axios JavaScript Library Hijacked
The Axios library, downloaded over 100 million times weekly, is hijacked to distribute remote access trojans (RATs).
Source cluster
Primary reporting
- It Security NewsCloud and SaaS Environments Now Top Targets for Attackers
Cite This Page
"Darktrace: 100M-Weekly Axios Downloads Hijacked as Cloud Top Attack Target." Cyber Intelligence Brief, August 5, 2026. https://getcyberbrief.com/story/darktrace-100m-axios-hijack-cloud-attack-target
How we covered this story
Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled cybersecurity-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |