axios Compromised on npm - Malicious Versions Drop Remote Access Trojan

2026-03-31 Step Security

https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan

Thumbnail for axios Compromised on npm - Malicious Versions Drop Remote Access Trojan

StepSecurity identified malicious npm releases [email protected] and [email protected] published through compromised maintainer credentials rather than the project’s normal GitHub Actions OIDC Trusted Publisher flow. The attacker added an unused runtime dependency, [email protected], whose postinstall script acted as a cross-platform RAT dropper for macOS, Windows, and Linux. The dropper decoded obfuscated strings at runtime, contacted http://sfrclak.com:8000/6202033, fetched platform-specific second-stage payloads, and then attempted to remove forensic traces by deleting or replacing its own package metadata. Harden-Runner observed anomalous outbound connections to sfrclak.com:8000 in CI, highlighting how a poisoned top-10 npm package could compromise developer workstations and build environments at large scale.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN sfrclak.com 2026-03-30 2026-04-20
URL http://sfrclak.com:8000/ 2026-03-31 2026-04-17
EMAIL [email protected] 2026-03-30 2026-04-17
EMAIL [email protected] 2026-03-30 2026-04-17
URL http://sfrclak.com:8000/6202033 2026-03-30 2026-04-17
IPv4 142.11.206.73 2026-03-30 2026-04-17
HASH d6f3f62fd3b9f5432f5782b62d8cfd5… 2026-03-30 2026-04-04
HASH 07d889e2dadce6f3910dcbc253317d2… 2026-03-30 2026-04-04

Related Reports

« Back