logo

Attackers hijack Axios npm account to spread RAT malware

ID: e5d5b26c-439f-540a-87a0-3ebd8035775b

STIX ID: report--e5d5b26c-439f-540a-87a0-3ebd8035775b

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-03-31

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Threat actors compromised the npm account of the widely used Axios library and published malicious releases (1.14.1 and 0.30.4) that injected a hidden dependency (plain-crypto-js) which deployed a cross-platform RAT on macOS, Windows, and Linux via obfuscated post-install scripts; researchers observed second-stage C2-backed binaries (including a C++ macOS RAT), self-deleting behavior, and related malicious packages (@shadanai/openclaw, @qqbrowser/openclaw-qbot), and advised checking for the specific versions, the plain-crypto-js dependency, and RAT artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.