Axios供应链攻击事件再追踪:线索直指Lazarus组织
2026-04-01 • Qihoo360 • Follow-up on the Axios Supply Chain Attack: Clues Point Directly to the Lazarus Group •
360 attributes the Axios npm supply-chain compromise to Lazarus with strong confidence, citing overlaps with GhostCall activity and RustBucket-related macOS components. Attackers hijacked the axios maintainer account and published malicious [email protected] and [email protected] releases that introduced the previously unused dependency [email protected] to execute a postinstall cross-platform RAT. The report links the incident to earlier activity using Telegram-to-meeting lures, PowerShell execution, credential theft, Run key persistence named MicrosoftUpdate, and payload delivery from domains such as microsmeet[.]xyz and bluyy[.]com. It also highlights RustBucket-adjacent macOS build strings such as macWebT and provides IOCs including kenaikoda[.]com, teams.onlivecall[.]com, 23.254.204[.]101, and multiple hashes for detection.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 41372946fe231c73750428700f6015fb | 2026-04-01 | 2026-04-01 |
| HASH | 3f47643c7a5cbf132f46b4cba75d1aa3 | 2026-04-01 | 2026-04-01 |
| HASH | db07741e586bfae526730c592a2ffe6a | 2026-04-01 | 2026-04-01 |
| HASH | ea3192f64b9988889d5f8c61be637d2a | 2026-04-01 | 2026-04-01 |
| DOMAIN | kenaikoda.com | 2026-04-01 | 2026-04-01 |
| DOMAIN | teams.onlivecall.com | 2026-04-01 | 2026-04-01 |
| IPv4 | 23.254.204.101 | 2026-04-01 | 2026-04-01 |
| HASH | 182760cbe11fa0316abfb8b7b00b63f… | 2023-04-21 | 2026-04-01 |