북한 연계 그룹의 AXIOS 공급망 공격
2026-04-01 • Secu I • North Korea-Linked Group's AXIOS Supply Chain Attack •
SECUI STIC analyzes an Axios supply-chain compromise in which attackers stole maintainer credentials and altered npm installation behavior so a malicious setup.js loader ran automatically when affected packages were installed. The loader used custom obfuscation, Base64 decoding, and XOR decryption with the fixed key OrDeR_7077 to recover strings and assemble downloader behavior tailored to the infected system. The report says infrastructure used in the attack partially overlapped with infrastructure previously observed in North Korea-linked activity, and it cites that overlap as the basis for pointing to a North Korean threat group. Defensive guidance focuses on checking exposure to Axios 1.14.1 and 0.30.4, looking for %PROGRAMDATA%\wt.exe, reviewing traffic to 142.11.206.73, and rotating credentials used on infected systems.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | sfrclak.com | 2026-03-30 | 2026-04-20 |
| HASH | 58401c195fe0a6204b42f5f90995ece… | 2026-03-31 | 2026-04-17 |
| HASH | 5bb67e88846096f1f8d42a0f0350c9c… | 2026-03-31 | 2026-04-17 |
| HASH | f7d335205b8d7b20208fb3ef93ee6dc… | 2026-03-31 | 2026-04-17 |
| HASH | e10b1fa84f1d6481625f741b6989278… | 2026-03-31 | 2026-04-17 |
| HASH | fcb81618bb15edfdedfb638b4c08a2a… | 2026-03-30 | 2026-04-17 |
| IPv4 | 142.11.206.73 | 2026-03-30 | 2026-04-17 |