Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account
ID: 9cde4ac1-57c1-5e72-b759-567598ea0578
STIX ID: report--9cde4ac1-57c1-5e72-b759-567598ea0578
Feed Name: The Hacker News
A supply-chain compromise of the Axios npm package (releases 1.14.1 and 0.30.4) injected a fake dependency, [email protected], whose postinstall script acts as a Node.js dropper to deploy platform-specific RATs for macOS, Windows and Linux; the attacker used a compromised maintainer account to publish poisoned releases, staged multi-OS payloads in advance, and the malware self-deletes and swaps manifests to hide traces. Users are advised to downgrade to safe Axios versions, rotate credentials, remove the malicious package from node_modules, check for RAT artifacts (/Library/Caches/com.apple.act.mond, %PROGRAMDATA%\wt.exe, /tmp/ld.py), audit CI/CD installs, and block the C2 domain (sfrclak.com).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
