logo

Supply chain attack on Axios npm package: Scope, impact, and remediations

ID: e6dd4fc0-a7d1-5447-9af3-1f9dcd53c86a

STIX ID: report--e6dd4fc0-a7d1-5447-9af3-1f9dcd53c86a

Feed Name: Security Boulevard

Threat Score
90/100

Date Published: 2026-03-31

Date Updated: 2026-04-22

Author: Ron Popov

...
...

This report documents a confirmed supply-chain compromise of the popular Axios npm package where attackers published malicious versions (1.14.1 and 0.30.4) that pull a dependency named "plain-crypto-js" which runs a postinstall dropper (setup.js, SHA256: e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09) contacting C2 sfrclak.com to deploy a cross-platform RAT capable of credential and API key theft; organizations are advised to treat affected hosts as fully compromised, quarantine, rotate secrets, and scan for the listed IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.