logo

Elastic releases detections for the Axios supply chain compromise

ID: c531668d-7f78-54b7-82ba-fbeb996f5cf5

STIX ID: report--c531668d-7f78-54b7-82ba-fbeb996f5cf5

Feed Name: Elastic Security Labs

Threat Score
90/100

Date Published: 2026-04-01

Date Updated: 2026-04-27

...
...

Elastic Security Labs describes a supply-chain attack that compromised axios npm releases by adding a postinstall transitive dependency ([email protected]) which spawns native shells to download and detach cross-platform payloads: a Python RAT (Linux), a PowerShell/.NET RAT (Windows), and a Mach-O backdoor (macOS). The report provides behavioral detection rules (process ancestry, detached execution, network retrieval), file/network IOCs (hashes, domain sfrclak.com, IP 142.11.206.73), and persistence indicators to aid rapid detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.