Attackers hijack Axios npm account to spread RAT malware
ID: e5d5b26c-439f-540a-87a0-3ebd8035775b
STIX ID: report--e5d5b26c-439f-540a-87a0-3ebd8035775b
Feed Name: Security Affairs
Threat actors compromised the npm account of the widely used Axios library and published malicious releases (1.14.1 and 0.30.4) that injected a hidden dependency (plain-crypto-js) which deployed a cross-platform RAT on macOS, Windows, and Linux via obfuscated post-install scripts; researchers observed second-stage C2-backed binaries (including a C++ macOS RAT), self-deleting behavior, and related malicious packages (@shadanai/openclaw, @qqbrowser/openclaw-qbot), and advised checking for the specific versions, the plain-crypto-js dependency, and RAT artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
