Mitigating the Axios npm supply chain compromise
ID: c012bf44-e234-5ef3-9444-de5c8eb5f015
STIX ID: report--c012bf44-e234-5ef3-9444-de5c8eb5f015
Feed Name: Microsoft Security
Date Published: 2026-04-01
Date Updated: 2026-04-28
Author: Microsoft Threat Intelligence and Microsoft Defender Security Research Team
## Executive summary Microsoft Threat Intelligence discovered that two Axios npm releases (1.14.1 and 0.30.4) were maliciously published with an injected dependency ([email protected]) that executes at install time to contact a Sapphire Sleet-owned C2 (sfrclak.com:8000/6202033) and deliver OS-specific RATs for Windows, macOS, and Linux; the report attributes the activity to the North Korean actor Sapphire Sleet, lists IoCs (domain, IP, file hashes, artifacts), and provides detection, mitigation, and hunting guidance for affected organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
