logo

Mitigating the Axios npm supply chain compromise

ID: c012bf44-e234-5ef3-9444-de5c8eb5f015

STIX ID: report--c012bf44-e234-5ef3-9444-de5c8eb5f015

Feed Name: Microsoft Security

Threat Score
90/100

Date Published: 2026-04-01

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence and Microsoft Defender Security Research Team

...
...

## Executive summary Microsoft Threat Intelligence discovered that two Axios npm releases (1.14.1 and 0.30.4) were maliciously published with an injected dependency ([email protected]) that executes at install time to contact a Sapphire Sleet-owned C2 (sfrclak.com:8000/6202033) and deliver OS-specific RATs for Windows, macOS, and Linux; the report attributes the activity to the North Korean actor Sapphire Sleet, lists IoCs (domain, IP, file hashes, artifacts), and provides detection, mitigation, and hunting guidance for affected organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.