logo

Compromised axios npm package delivers cross-platform RAT

ID: 05187aba-a7c3-5bf1-804b-5e670803274f

STIX ID: report--05187aba-a7c3-5bf1-804b-5e670803274f

Feed Name: Datadog Security Labs

Threat Score
75/100

Date Published: 2026-03-31

Date Updated: 2026-04-27

...
...

On 31 March 2026 an attacker hijacked an axios maintainer account and published malicious releases ([email protected] and 0.30.4) that added a typosquatted dependency plain-crypto-js which used a postinstall script to download and execute a cross-platform RAT from sfrclak.com; npm removed the compromised packages within about three hours. The report analyzes the dropper and platform-specific payloads (macOS Mach-O, Windows PowerShell, Linux Python), documents C2 indicators, file and registry artifacts, timeline and mitigation steps, and notes the RAT contained bugs limiting its effectiveness despite the high distribution risk due to axios's popularity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.