logo

Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account

ID: 9cde4ac1-57c1-5e72-b759-567598ea0578

STIX ID: report--9cde4ac1-57c1-5e72-b759-567598ea0578

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-03-31

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A supply-chain compromise of the Axios npm package (releases 1.14.1 and 0.30.4) injected a fake dependency, [email protected], whose postinstall script acts as a Node.js dropper to deploy platform-specific RATs for macOS, Windows and Linux; the attacker used a compromised maintainer account to publish poisoned releases, staged multi-OS payloads in advance, and the malware self-deletes and swaps manifests to hide traces. Users are advised to downgrade to safe Axios versions, rotate credentials, remove the malicious package from node_modules, check for RAT artifacts (/Library/Caches/com.apple.act.mond, %PROGRAMDATA%\wt.exe, /tmp/ld.py), audit CI/CD installs, and block the C2 domain (sfrclak.com).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.