logo

STARDUST CHOLLIMA Likely Compromises Axios npm Package

ID: f7c7a4a8-08e3-57a0-ac5f-70d0c47b85cd

STIX ID: report--f7c7a4a8-08e3-57a0-ac5f-70d0c47b85cd

Feed Name: Crowdstrike Blog

Threat Score
88/100

Date Published: 2026-04-01

Date Updated: 2026-04-27

Author: Counter Adversary Operations

...
...

On March 31, 2026, a supply‑chain compromise of the Axios npm package using stolen maintainer credentials resulted in deployment of updated cross‑platform ZshBucket implants. CrowdStrike attributes the activity with moderate confidence to STARDUST CHOLLIMA based on malware code reuse and overlapping infrastructure (notably domain sfrclak.com and associated IPs), and notes enhanced JSON-based messaging and expanded remote‑control commands enabling binary injection, arbitrary execution, filesystem enumeration, and data collection; the incident highlights a scalable APT supply‑chain operation targeting widely used developer ecosystems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.