logo

Axios npm Supply Chain Breach: Microsoft Shares Mitigation Steps

ID: f234bd5f-9b25-5c61-81f2-78b03fb02f5e

STIX ID: report--f234bd5f-9b25-5c61-81f2-78b03fb02f5e

Feed Name: GBHackers

Threat Score
91/100

Date Published: 2026-04-02

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Microsoft warns that two malicious Axios npm releases (1.14.1 and 0.30.4) contained a hidden install-time dependency that reached out to C2 infrastructure (sfrclak.com, IP 142.11.206.73) to download platform-specific RATs; activity is attributed to the North Korean group Sapphire Sleet. The compromise leverages npm lifecycle hooks to execute during npm install/update across developer workstations, CI/CD runners, and production systems, persisting on macOS, Windows, and Linux; Microsoft recommends rotating exposed secrets, downgrading to safe Axios versions, scanning for the affected packages and outbound connections, and hardening npm/CI publishing practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.