logo

Axios supply chain attack chops away at npm trust

ID: 4c6509c4-31ac-5a03-a3ae-32c97ea37d0d

STIX ID: report--4c6509c4-31ac-5a03-a3ae-32c97ea37d0d

Feed Name: Malwarebytes Blog

Threat Score
85/100

Date Published: 2026-03-31

Date Updated: 2026-04-28

...
...

Malicious npm packages masquerading as legitimate Axios releases ([email protected] and [email protected]) and a dependency ([email protected]) were published using compromised maintainer credentials. The packages used a postinstall script to download an obfuscated dropper that retrieved platform-specific RAT payloads (macOS, Windows, Linux), potentially exposing secrets from developer/build environments; identified IOCs include domain sfrclak.com, IP 142.11.206.73, file paths on macOS/Linux/Windows, and SHA-256 checksums for the malicious packages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.