logo

Axios NPM Package Supply Chain Compromise Leads to RAT Deployment

ID: 4bc3ac2b-2310-5e94-a257-8c3b58006e7e

STIX ID: report--4bc3ac2b-2310-5e94-a257-8c3b58006e7e

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
90/100

Date Published: 2026-04-09

Date Updated: 2026-04-28

Author: Mahadev Joshi and Sho Kishimoto

...
...

A supply‑chain compromise of the Axios npm package (malicious versions observed: [email protected] and [email protected]) executed a hidden dependency via npm postinstall scripts to download and deploy a RAT. LevelBlue detected post‑install execution, abnormal parent‑child process chains (npm/node → cmd.exe/powershell → curl/wget), and outbound C2 traffic; the report supplies SHA256 hashes, C2 IP/domain/URL, hunting queries, and containment/remediation recommendations (isolate/reimage, rotate credentials, disable npm scripts, enforce lockfiles).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.