Elastic releases detections for the Axios supply chain compromise
ID: 4dce9430-bb0a-5c46-a9cf-faf6fceca02c
STIX ID: report--4dce9430-bb0a-5c46-a9cf-faf6fceca02c
Feed Name: Elastic Security Labs
Date Published: 2026-04-01
Date Updated: 2026-08-27
Author: Ruben Groenewoud,Samir Bousseaden,Salim Bitam,Joe Desimone,Colson Wilhoit,Andrew Pease
Elastic Security Labs describes a supply-chain compromise of the axios npm package (malicious versions 1.14.1 and 0.30.4) that added a transitive dependency ([email protected]) which executed during installation to fetch and launch cross-platform second-stage RATs; the report details platform-specific delivery/execution chains, persistence mechanisms, C2 indicators, file and network IOCs, and behavioral detection rules that reliably catch the installation-to-delivery stage across Linux, Windows, and macOS.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
