logo

Supply chain attack on Axios npm package: Scope, impact, and remediations

ID: ddd471f0-f8ad-5cd9-b18b-8fff1d47f680

STIX ID: report--ddd471f0-f8ad-5cd9-b18b-8fff1d47f680

Feed Name: Tenable Blog

Threat Score
90/100

Date Published: 2026-03-31

Date Updated: 2026-05-01

Author: Ron Popov

...
...

A critical supply-chain compromise of the Axios npm package was discovered: attackers published malicious versions 1.14.1 and 0.30.4 that add a dependency "plain-crypto-js" which uses an npm postinstall hook to run a double-obfuscated dropper (setup.js). The dropper identifies the OS and contacts C2 sfrclak.com:8000 to fetch a platform-specific RAT capable of exfiltrating credentials and API keys; IOCs include the dropper SHA256 e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09 and the C2 domain, and the report urges immediate scanning, quarantine, incident response, and secret rotation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.