axios compromised on npm: maintainer account hijacked, RAT deployed
2026-03-30 • Aikido •
https://www.aikido.dev/blog/axios-npm-compromised-maintainer-hijacked-rat
Attackers hijacked the jasonsaayman npm account and published malicious [email protected] and [email protected], adding [email protected] solely to run a postinstall dropper. The package contacted sfrclak[.]com:8000 and installed platform-specific RAT payloads on macOS, Windows, and Linux, including /Library/Caches/com.apple.act.mond, %PROGRAMDATA%\wt.exe, and /tmp/ld.py. Aikido notes the dropper deleted setup.js and replaced its package metadata with a clean stub, so responders should rely on logs and artifact checks rather than node_modules inspection alone. The report advises rebuilding affected hosts and rotating exposed npm, cloud, SSH, CI/CD, wallet, and environment secrets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | sfrclak.com | 2026-03-30 | 2026-04-20 |
| HASH | 617b67a8e1210e4fc87c92d1d1da45a… | 2026-03-30 | 2026-04-17 |
| HASH | 92ff08773995ebc8d55ec4b8e1a225d… | 2026-03-30 | 2026-04-17 |
| HASH | fcb81618bb15edfdedfb638b4c08a2a… | 2026-03-30 | 2026-04-17 |
| [email protected] | 2026-03-30 | 2026-04-17 | |
| [email protected] | 2026-03-30 | 2026-04-17 | |
| URL | http://sfrclak.com:8000/6202033 | 2026-03-30 | 2026-04-17 |
| IPv4 | 142.11.206.73 | 2026-03-30 | 2026-04-17 |
| HASH | d6f3f62fd3b9f5432f5782b62d8cfd5… | 2026-03-30 | 2026-04-04 |
| HASH | 07d889e2dadce6f3910dcbc253317d2… | 2026-03-30 | 2026-04-04 |
| HASH | 2553649f2322049666871cea80a5d0d… | 2026-03-30 | 2026-04-04 |