logo

Hackers compromise Axios npm package to drop cross-platform malware

ID: e49ecffa-b396-5850-aafc-e63fc6b57e9a

STIX ID: report--e49ecffa-b396-5850-aafc-e63fc6b57e9a

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-03-31

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Attackers hijacked the Axios npm maintainer account and published two malicious package versions that added a dependency executing a post-install dropper; the dropper fetched OS-specific RAT payloads for Windows, macOS, and Linux, used self-cleaning to hinder forensics, and exposed likely wide impact given Axios's large install base. Researchers published IoCs (including sfrclak.com) and recommend checking for [email protected], [email protected], and any plain-crypto-js package, rotating credentials, and downgrading to known-good Axios versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.