Supply Chain Malware Alert: plain-crypto-js Compromises Axios Packages
ID: babf6c71-9708-57d5-98ef-437e90bc4b7a
STIX ID: report--babf6c71-9708-57d5-98ef-437e90bc4b7a
Feed Name: Resecurity
Threat Score
The report documents a high-impact supply-chain malware campaign in which a trojanized npm package (plain-crypto-js) embedded in compromised Axios versions leveraged npm postinstall hooks and advanced obfuscation to deploy cross-platform RATs that exfiltrate credentials and maintain persistent remote control; it includes decoded payload behavior, MITRE ATT&CK mappings, IOCs (hashes, domains, IP), affected file paths, and remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
