logo

Axios supply chain attack chops away at npm trust

ID: 05e5826d-3545-58d4-a4ab-154dcec010ce

STIX ID: report--05e5826d-3545-58d4-a4ab-154dcec010ce

Feed Name: Security Boulevard

Threat Score
85/100

Date Published: 2026-03-31

Date Updated: 2026-04-22

Author: Malwarebytes

...
...

A supply‑chain attack on the Axios npm ecosystem delivered malicious versions that added a hidden dependency and used a postinstall script to download an obfuscated dropper and platform‑specific RAT for macOS, Windows, and Linux. The compromised packages reached millions of installs, risking exposure of build‑time secrets (API keys, deploy keys, tokens); the report provides IOCs (domain sfrclak.com, IP 142.11.206.73, file artefacts, and package SHA‑256 hashes) and advises treating any machine that installed the bad versions as fully compromised and rotating secrets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.