logo

Axios npm package compromised to deploy malware

ID: 58ff324c-2265-586e-a810-c19c641b6c0d

STIX ID: report--58ff324c-2265-586e-a810-c19c641b6c0d

Feed Name: Sophos Blogs

Threat Score
75/100

Date Published: 2026-03-31

Date Updated: 2026-04-30

...
...

This report catalogs indicators and artifacts from a malicious supply‑chain campaign distributing trojanized Axios/npm packages (e.g., axios-1.14.1.tgz, axios-0.30.4.tgz, plain-crypto-js-4.2.1.tgz) and related payloads for Windows, macOS, and Linux. It provides MD5/SHA1/SHA256 hashes, filenames (setup.js, system.bat, ld.py, com.apple.act.mond), C2 domains and URLs (sfrclak.com, callnrwise.com, http://sfrclak.com:8000/6202033), an IP (142.11.206.73), attacker email addresses ([email protected], [email protected]), and Windows file locations such as C:\ProgramData\wt.exe and C:\ProgramData\system.bat; the Windows second-stage is identified as a PowerShell RAT.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.