logo

Poisoned Axios: npm Account Takeover, 50 Million Downloads, and a RAT That Vanishes After Install

ID: 957b6f4c-1ff8-5cdf-8076-e29bac99aa75

STIX ID: report--957b6f4c-1ff8-5cdf-8076-e29bac99aa75

Feed Name: Security Boulevard

Threat Score
85/100

Date Published: 2026-03-31

Date Updated: 2026-04-22

Author: Tom Abai

...
...

On March 30–31, 2026 attackers published malicious axios packages (1.14.1 and 0.30.4) to npm by compromising a maintainer account; both releases added [email protected], which contained an obfuscated postinstall dropper that fetched platform-specific payloads and installed a cross-platform RAT (macOS Mach‑O confirmed) that beacons to http://sfrclak.com:8000/6202033. The dropper self‑erases and restores a clean package.json to evade post‑install audits; axios has deprecated the malicious versions and the packages were removed, but any system that ran npm install on those versions should be treated as compromised and follow the provided remediation and detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.