Axios npm attack: rapid hunting with KQL and response guide
2026-04-03 • NVISO •
https://blog.nviso.eu/2026/04/03/the-axios-npm-supply-chain-incident-fake-dependency-real-backdoor/
NVISO describes hunting and response activity for the Axios npm supply-chain incident, where compromised Axios releases added the trojanized [email protected] dependency and deployed cross-platform RAT payloads. Its MDR telemetry observed activity mainly on developer workstations and Docker containers, with Windows infections launching setup.js through node.exe, copying PowerShell to C:\ProgramData\wt.exe, staging 6202033.vbs and 6202033.ps1, and communicating with sfrclak.com:8000/6202033. The second-stage PowerShell behavior included system and filesystem reconnaissance, local enumeration, C2 communication, and persistence via a Run-key value named MicrosoftUpdate pointing to C:\ProgramData\system.bat. NVISO provides Defender KQL hunts for network, process, file, and registry traces, including domains sfrclak.com, callnrwise.com, calltan.com, IPs 142.11.206.73 and 23.254.167.216, and hashes for setup.js, payloads, packages, and persistence artifacts. The guidance emphasizes isolating affected endpoints, rotating secrets, blocking IOCs, and rebuilding CI/CD artifacts from clean pinned dependency versions.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | sfrclak.com | 2026-03-30 | 2026-04-20 |
| HASH | 58401c195fe0a6204b42f5f90995ece… | 2026-03-31 | 2026-04-17 |
| HASH | ed8560c1ac7ceb6983ba995124d5917… | 2026-03-31 | 2026-04-17 |
| HASH | 59336a964f110c25c112bcc5adca709… | 2026-03-31 | 2026-04-17 |
| HASH | 5bb67e88846096f1f8d42a0f0350c9c… | 2026-03-31 | 2026-04-17 |
| HASH | f7d335205b8d7b20208fb3ef93ee6dc… | 2026-03-31 | 2026-04-17 |
| HASH | e10b1fa84f1d6481625f741b6989278… | 2026-03-31 | 2026-04-17 |
| DOMAIN | calltan.com | 2026-03-31 | 2026-04-17 |
| DOMAIN | callnrwise.com | 2026-03-31 | 2026-04-17 |
| HASH | 617b67a8e1210e4fc87c92d1d1da45a… | 2026-03-30 | 2026-04-17 |
| HASH | 92ff08773995ebc8d55ec4b8e1a225d… | 2026-03-30 | 2026-04-17 |
| HASH | fcb81618bb15edfdedfb638b4c08a2a… | 2026-03-30 | 2026-04-17 |
| IPv4 | 142.11.206.73 | 2026-03-30 | 2026-04-17 |
| IPv4 | 23.254.167.216 | 2025-01-14 | 2026-04-17 |
| HASH | e49c2732fb9861548208a78e72996b9… | 2026-03-31 | 2026-04-03 |