Axios Hijacked: npm Account Takeover Deploys Cross-Platform RAT to Millions
ID: 7249349a-a7b7-528e-93a5-36122c2b4c30
STIX ID: report--7249349a-a7b7-528e-93a5-36122c2b4c30
Feed Name: Security Boulevard
A compromised npm maintainer account was used to publish malicious versions of Axios (1.14.1 and 0.30.4) that added a phantom dependency (plain-crypto-js) executing a postinstall dropper which fetches and installs a persistent cross-platform RAT on macOS, Windows, and Linux; the payload self-deletes within seconds, making post‑install forensics difficult. The malicious packages were live for a short window on 30–31 March 2026 and include explicit IOCs (C2 sfrclak.com / 142.11.206.73:8000, file paths, and SHA‑256 hashes); affected teams are advised to check lockfiles, search for artifacts, downgrade to safe versions, rebuild compromised hosts, rotate credentials, and block the C2.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
