logo

The Axios npm supply chain incident: fake dependency, real backdoor

ID: d69166bc-a052-5dda-8ade-47dbbad20031

STIX ID: report--d69166bc-a052-5dda-8ade-47dbbad20031

Feed Name: NVISO Labs

Threat Score
85/100

Date Published: 2026-04-03

Date Updated: 2026-05-13

Author: Thomas Papaloukas

...
...

On 2026-03-31 attackers published two trojanized Axios npm versions that introduced a malicious dependency ([email protected]) whose postinstall dropper fetched OS-specific RAT payloads; though the packages were removed within hours, multiple detections occurred across developer workstations and Docker containers. The report documents the Windows infection chain (PowerShell renamed to C:\ProgramData\wt.exe, 6202033.vbs/6202033.ps1 second-stage scripts, registry persistence via MicrosoftUpdate), provides IOCs (hashes, domains, IPs, URL), KQL hunting queries for detection, and recommended containment and remediation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.