axios Compromised on npm - Malicious Versions Drop Remote Access Trojan
2026-03-31 • Step Security •
StepSecurity identified malicious npm releases [email protected] and [email protected] published through compromised maintainer credentials rather than the project’s normal GitHub Actions OIDC Trusted Publisher flow. The attacker added an unused runtime dependency, [email protected], whose postinstall script acted as a cross-platform RAT dropper for macOS, Windows, and Linux. The dropper decoded obfuscated strings at runtime, contacted http://sfrclak.com:8000/6202033, fetched platform-specific second-stage payloads, and then attempted to remove forensic traces by deleting or replacing its own package metadata. Harden-Runner observed anomalous outbound connections to sfrclak.com:8000 in CI, highlighting how a poisoned top-10 npm package could compromise developer workstations and build environments at large scale.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | sfrclak.com | 2026-03-30 | 2026-04-20 |
| URL | http://sfrclak.com:8000/ | 2026-03-31 | 2026-04-17 |
| [email protected] | 2026-03-30 | 2026-04-17 | |
| [email protected] | 2026-03-30 | 2026-04-17 | |
| URL | http://sfrclak.com:8000/6202033 | 2026-03-30 | 2026-04-17 |
| IPv4 | 142.11.206.73 | 2026-03-30 | 2026-04-17 |
| HASH | d6f3f62fd3b9f5432f5782b62d8cfd5… | 2026-03-30 | 2026-04-04 |
| HASH | 07d889e2dadce6f3910dcbc253317d2… | 2026-03-30 | 2026-04-04 |