북한 연계 그룹의 AXIOS 공급망 공격

2026-04-01 Secu I North Korea-Linked Group's AXIOS Supply Chain Attack

https://stic.secui.com/main/main/threatInfo?id=371&lang=ko

Thumbnail for 북한 연계 그룹의 AXIOS 공급망 공격

SECUI STIC analyzes an Axios supply-chain compromise in which attackers stole maintainer credentials and altered npm installation behavior so a malicious setup.js loader ran automatically when affected packages were installed. The loader used custom obfuscation, Base64 decoding, and XOR decryption with the fixed key OrDeR_7077 to recover strings and assemble downloader behavior tailored to the infected system. The report says infrastructure used in the attack partially overlapped with infrastructure previously observed in North Korea-linked activity, and it cites that overlap as the basis for pointing to a North Korean threat group. Defensive guidance focuses on checking exposure to Axios 1.14.1 and 0.30.4, looking for %PROGRAMDATA%\wt.exe, reviewing traffic to 142.11.206.73, and rotating credentials used on infected systems.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN sfrclak.com 2026-03-30 2026-04-20
HASH 58401c195fe0a6204b42f5f90995ece… 2026-03-31 2026-04-17
HASH 5bb67e88846096f1f8d42a0f0350c9c… 2026-03-31 2026-04-17
HASH f7d335205b8d7b20208fb3ef93ee6dc… 2026-03-31 2026-04-17
HASH e10b1fa84f1d6481625f741b6989278… 2026-03-31 2026-04-17
HASH fcb81618bb15edfdedfb638b4c08a2a… 2026-03-30 2026-04-17
IPv4 142.11.206.73 2026-03-30 2026-04-17

Related Reports

« Back