Compromised axios npm package delivers cross-platform RAT
ID: 05187aba-a7c3-5bf1-804b-5e670803274f
STIX ID: report--05187aba-a7c3-5bf1-804b-5e670803274f
Feed Name: Datadog Security Labs
On 31 March 2026 an attacker hijacked an axios maintainer account and published malicious releases ([email protected] and 0.30.4) that added a typosquatted dependency plain-crypto-js which used a postinstall script to download and execute a cross-platform RAT from sfrclak.com; npm removed the compromised packages within about three hours. The report analyzes the dropper and platform-specific payloads (macOS Mach-O, Windows PowerShell, Linux Python), documents C2 indicators, file and registry artifacts, timeline and mitigation steps, and notes the RAT contained bugs limiting its effectiveness despite the high distribution risk due to axios's popularity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
