Axios attacker strikes again! Three NPM packages have been hiding in plain sight for two months

2026-05-19 OSM

https://opensourcemalware.com/blog/axios-attacker-additional-npm-packages

Thumbnail for Axios attacker strikes again! Three NPM packages have been hiding in plain sight for two months

OpenSourceMalware found three malicious npm packages linked to the March 2026 Axios compromise through the shared XOR key OrDeR_7077, while using separate C2 infrastructure at 18.208.244.120:9999. The packages redeem-onchain-sdk, nicegui, and period-newline used npm postinstall execution, self-deletion, package.json rewriting, and multi-layer obfuscation to conceal an infostealer. The malware collected host and user details, external IP data, developer credentials, cloud and npm secrets, SSH material, Docker registry authentication, browser login data, and recent git history before encrypted TCP exfiltration. The earlier Axios campaign was attributed by Google Threat Intelligence Group to UNC1069, a financially motivated North Korea-nexus actor, and Microsoft tracks the same activity as Sapphire Sleet.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 18.208.244.120 2026-05-19 2026-05-19
DOMAIN sfrclak.com 2026-03-30 2026-04-20
IPv4 142.11.206.73 2026-03-30 2026-04-17

Related Actors

Related Reports

« Back