Axios supply chain attack chops away at npm trust
ID: 05e5826d-3545-58d4-a4ab-154dcec010ce
STIX ID: report--05e5826d-3545-58d4-a4ab-154dcec010ce
Feed Name: Security Boulevard
A supply‑chain attack on the Axios npm ecosystem delivered malicious versions that added a hidden dependency and used a postinstall script to download an obfuscated dropper and platform‑specific RAT for macOS, Windows, and Linux. The compromised packages reached millions of installs, risking exposure of build‑time secrets (API keys, deploy keys, tokens); the report provides IOCs (domain sfrclak.com, IP 142.11.206.73, file artefacts, and package SHA‑256 hashes) and advises treating any machine that installed the bad versions as fully compromised and rotating secrets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
