logo

Poisoned Axios Package Spreads Cross-Platform Malware via Phantom Dependency

ID: 18ffd86f-3a65-5dd1-9d86-45d77e09f858

STIX ID: report--18ffd86f-3a65-5dd1-9d86-45d77e09f858

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-04-06

Date Updated: 2026-06-18

Author: Mayura Kathir

...
...

Hackers hijacked an Axios maintainer's npm account and published two malicious Axios releases (1.14.1 and 0.30.4) that introduced a phantom dependency (plain-crypto-js) containing an obfuscated postinstall hook which deployed a cross-platform remote access trojan (macOS, Windows, Linux). The dropper used layered obfuscation, platform‑specific payload delivery, and anti‑forensics to erase install traces and communicated with C2 at sfrclak.com:8000; npm removed the packages within hours but telemetry shows multiple sectors (government, finance, healthcare, technology, manufacturing) were impacted and defenders are advised to pin safe versions, remove artifacts, rotate secrets, and enforce ignore-scripts controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.