logo

This Sophisticated Scam Should Be a Warning To All Companies

ID: dc877671-4c56-5afb-affe-3ecfd5d8cded

STIX ID: report--dc877671-4c56-5afb-affe-3ecfd5d8cded

Feed Name: KnowBe4 Blog

Threat Score
90/100

Date Published: 2026-04-21

Date Updated: 2026-04-28

Author: Roger Grimes

...
...

**Executive Summary:** On March 31, 2026 attackers likely linked to a nation-state compromised an Axios npm maintainer account and published malicious axios package versions that installed a cross-platform RAT via a fake dependency and post-install script; the attack used sophisticated social engineering (fake Slack/Teams workspace and a Click-Fix PowerShell prompt), was live for a short period, impacted roughly 3% of environments, and the report recommends education, phishing-resistant MFA, and developer isolation as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.