logo

Axios Under Siege: Critical npm Supply Chain Attack Hijacks Lead Maintainer to Drop Multi-Platform RAT

ID: 2f7a7eec-f20b-564c-8b43-655301261284

STIX ID: report--2f7a7eec-f20b-564c-8b43-655301261284

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-03-31

Date Updated: 2026-04-23

Author: Ddos

...
...

Security researchers warn that two malicious axios npm releases were published after a maintainer account was compromised; the releases include a hidden dependency (plain-crypto-js) whose postinstall script acts as a cross-platform RAT dropper that contacts C2 at sfrclak.com, stages payloads, executes shell commands, and deletes forensic artifacts — organizations should assume compromise, scan for IOCs, revert to known-good versions, rotate credentials, and harden CI/CD to block postinstall scripts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.