Axios供应链攻击事件再追踪:线索直指Lazarus组织

2026-04-01 Qihoo360 Follow-up on the Axios Supply Chain Attack: Clues Point Directly to the Lazarus Group

https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247508249&idx=1&sn=d50892ac7b48a52ff293889bb77c800f

360 attributes the Axios npm supply-chain compromise to Lazarus with strong confidence, citing overlaps with GhostCall activity and RustBucket-related macOS components. Attackers hijacked the axios maintainer account and published malicious [email protected] and [email protected] releases that introduced the previously unused dependency [email protected] to execute a postinstall cross-platform RAT. The report links the incident to earlier activity using Telegram-to-meeting lures, PowerShell execution, credential theft, Run key persistence named MicrosoftUpdate, and payload delivery from domains such as microsmeet[.]xyz and bluyy[.]com. It also highlights RustBucket-adjacent macOS build strings such as macWebT and provides IOCs including kenaikoda[.]com, teams.onlivecall[.]com, 23.254.204[.]101, and multiple hashes for detection.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 41372946fe231c73750428700f6015fb 2026-04-01 2026-04-01
HASH 3f47643c7a5cbf132f46b4cba75d1aa3 2026-04-01 2026-04-01
HASH db07741e586bfae526730c592a2ffe6a 2026-04-01 2026-04-01
HASH ea3192f64b9988889d5f8c61be637d2a 2026-04-01 2026-04-01
DOMAIN kenaikoda.com 2026-04-01 2026-04-01
DOMAIN teams.onlivecall.com 2026-04-01 2026-04-01
IPv4 23.254.204.101 2026-04-01 2026-04-01
HASH 182760cbe11fa0316abfb8b7b00b63f… 2023-04-21 2026-04-01

Related Actors

Related Reports

« Back