Axios Under Siege: Critical npm Supply Chain Attack Hijacks Lead Maintainer to Drop Multi-Platform RAT
ID: 2f7a7eec-f20b-564c-8b43-655301261284
STIX ID: report--2f7a7eec-f20b-564c-8b43-655301261284
Feed Name: securityonline.info
Security researchers warn that two malicious axios npm releases were published after a maintainer account was compromised; the releases include a hidden dependency (plain-crypto-js) whose postinstall script acts as a cross-platform RAT dropper that contacts C2 at sfrclak.com, stages payloads, executes shell commands, and deletes forensic artifacts — organizations should assume compromise, scan for IOCs, revert to known-good versions, rotate credentials, and harden CI/CD to block postinstall scripts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
