Axios supply chain attack (Incident)
ID: c13fdfe6-6fcf-59d8-8d2e-8b7926c2bb31
STIX ID: report--c13fdfe6-6fcf-59d8-8d2e-8b7926c2bb31
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2026-03-31
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Malicious versions of the npm package `axios` were published from a compromised maintainer account; they added a dependency on a trojanized package and included a dropper (`setup.js`) that downloaded platform-specific second-stage RATs from `sfrclak.com:8000`. The second-stage payloads (macOS Mach-O binary with code-signing capabilities, Windows PowerShell with registry persistence and re-download batch, and a Linux Python script) beaconed to the C2 every 60 seconds, provided remote shell and reconnaissance capabilities, and self-cleaned by restoring package.json and deleting the dropper after execution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
