Axios Supply Chain Attack Exposes Developers to Hidden Malware
ID: b916a56e-5c14-5307-8ddd-d5bd09c22814
STIX ID: report--b916a56e-5c14-5307-8ddd-d5bd09c22814
Feed Name: The Cyber Express
Threat Score
A compromised Axios maintainer npm account was used to publish poisoned releases ([email protected] and 0.30.4) that injected a fake dependency ([email protected]). The dependency executed a post-install script that fetched a cross-platform RAT from a C2 server, delivered macOS/Windows/Linux payloads, and performed cleanup and anti-forensics to hide the compromise; malicious packages were available for several hours before removal, potentially impacting millions of projects.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
