How we caught the Axios supply chain attack
ID: 3bf9b8a7-313f-50e9-bb0d-d20aaa106a0e
STIX ID: report--3bf9b8a7-313f-50e9-bb0d-d20aaa106a0e
Feed Name: Elastic Security Labs
This first‑hand account describes how an AI-based package-diffing proof-of-concept detected a major npm supply-chain compromise of axios that introduced a phantom dependency with a malicious postinstall hook (cross-platform RAT using steganography, obfuscation, and C2 exfiltration). The report ties the incident to a broader credential-theft campaign affecting Trivy, LiteLLM, and Telnyx, notes suspected DPRK/TeamPCP attribution, outlines the rapid response and detections, and recommends mitigations (soak time for new releases, credential rotation) while open-sourcing the monitoring tool.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
