Compromised NPM Package Axios

Trust Centre

background-image
Start your security review
View & download sensitive information
ControlK

Welcome to the Esri UK and Esri Ireland Trust Centre

Our commitment to information security and data privacy is embedded in every part of our business. Use this Trust Centre to learn about our security posture and request access to our security documentation.

We have established an Integrated Management System (IMS) that complies with ISO/IEC 27001:2022 (as well as BS EN ISO 9001:2015, BS EN ISO 14001:2015) standards.

A full list of Esri UK and Esri Ireland policies, and other relevant information, can be found in this Trust Centre.

Note: The scope of this Trust Centre is Esri UK and Esri Ireland, covering our back office systems and organisational approaches to information and data security. This Trust Centre does not cover Esri Inc or a detailed insight into Esri Inc ArcGIS products. A useful starting point to understand the relationship between Esri UK/Esri Ireland and Esri Inc can be found here in the Trust Centre.

The Esri Inc ArcGIS Trust Centre can be found here

Trust Centre Updates

Compromised NPM Package Axios

Copy link
Vulnerabilities

On 31st March 2026 two malicious versions of the axios package were briefly published to npm. These versions were available during an approximately three hour window before being replaced. The axios package is used extensively in other packages, some of which are used in Esri UK software products. However, no Esri UK software product was impacted by this attack and the malicious versions are not included in any Esri UK software.

Documents

Featured Documents

REPORTSArcGIS - GDPR - Data Security
If you need help using this Trust Centre, please contact us.
Contact support
Built onSafeBase by Drata Logo