logo

Supply Chain Compromise of axios npm Package

ID: 169c8a1c-16b4-520b-81ad-1e56a7a09af1

STIX ID: report--169c8a1c-16b4-520b-81ad-1e56a7a09af1

Feed Name: Huntress Blog

Threat Score
92/100

Date Published: 2026-03-31

Date Updated: 2026-04-28

...
...

**Executive summary:** Huntress investigated a coordinated supply-chain compromise of the widely used axios npm package that briefly (≈3 hours) delivered a malicious dependency ([email protected]) which executed a cross-platform RAT on any system that installed the backdoored axios releases; the RAT performed credential and filesystem reconnaissance, maintained a 60-second beacon to C2 (sfrclak.com:8000), supported remote commands including in-memory .NET injection, and established persistence on Windows and macOS. The report provides technical droppers and RAT analysis, IOCs (package hashes, binaries, domain/IP, file paths, registry keys), remediation steps (rebuild infected hosts, rotate credentials, pin safe axios versions, block C2), and notes ties to a DPRK-linked cluster.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.