Supply Chain Attacks Surge in March 2026
ID: a604409c-438a-5a0f-85a9-d436f044ade1
STIX ID: report--a604409c-438a-5a0f-85a9-d436f044ade1
Feed Name: Zscaler Security Research Blog
On 2026-03-30 researchers discovered an account-takeover supply-chain compromise of the Axios NPM package (affected versions 1.14.1 and 0.30.4) where attackers published malicious releases that add a hidden dependency (plain-crypto-js) containing a postinstall script to deploy a cross-platform RAT; the malware contacts C2 at sfrclak.com (and IP 142.11.206.73), fetches platform payloads, and attempts to cover its tracks by removing traces and restoring a clean package.json. Recommended mitigations include removing compromised packages, downgrading to known-good versions, revoking tokens, enforcing MFA, restricting package manager access in CI, and scanning/isolating potentially impacted systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
