Poisoned Axios Package Spreads Cross-Platform Malware via Phantom Dependency
ID: 18ffd86f-3a65-5dd1-9d86-45d77e09f858
STIX ID: report--18ffd86f-3a65-5dd1-9d86-45d77e09f858
Feed Name: GBHackers
Hackers hijacked an Axios maintainer's npm account and published two malicious Axios releases (1.14.1 and 0.30.4) that introduced a phantom dependency (plain-crypto-js) containing an obfuscated postinstall hook which deployed a cross-platform remote access trojan (macOS, Windows, Linux). The dropper used layered obfuscation, platform‑specific payload delivery, and anti‑forensics to erase install traces and communicated with C2 at sfrclak.com:8000; npm removed the packages within hours but telemetry shows multiple sectors (government, finance, healthcare, technology, manufacturing) were impacted and defenders are advised to pin safe versions, remove artifacts, rotate secrets, and enforce ignore-scripts controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
