Axios npm attack: rapid hunting with KQL and response guide

2026-04-03 NVISO

https://blog.nviso.eu/2026/04/03/the-axios-npm-supply-chain-incident-fake-dependency-real-backdoor/

Thumbnail for Axios npm attack: rapid hunting with KQL and response guide

NVISO describes hunting and response activity for the Axios npm supply-chain incident, where compromised Axios releases added the trojanized [email protected] dependency and deployed cross-platform RAT payloads. Its MDR telemetry observed activity mainly on developer workstations and Docker containers, with Windows infections launching setup.js through node.exe, copying PowerShell to C:\ProgramData\wt.exe, staging 6202033.vbs and 6202033.ps1, and communicating with sfrclak.com:8000/6202033. The second-stage PowerShell behavior included system and filesystem reconnaissance, local enumeration, C2 communication, and persistence via a Run-key value named MicrosoftUpdate pointing to C:\ProgramData\system.bat. NVISO provides Defender KQL hunts for network, process, file, and registry traces, including domains sfrclak.com, callnrwise.com, calltan.com, IPs 142.11.206.73 and 23.254.167.216, and hashes for setup.js, payloads, packages, and persistence artifacts. The guidance emphasizes isolating affected endpoints, rotating secrets, blocking IOCs, and rebuilding CI/CD artifacts from clean pinned dependency versions.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN sfrclak.com 2026-03-30 2026-04-20
HASH 58401c195fe0a6204b42f5f90995ece… 2026-03-31 2026-04-17
HASH ed8560c1ac7ceb6983ba995124d5917… 2026-03-31 2026-04-17
HASH 59336a964f110c25c112bcc5adca709… 2026-03-31 2026-04-17
HASH 5bb67e88846096f1f8d42a0f0350c9c… 2026-03-31 2026-04-17
HASH f7d335205b8d7b20208fb3ef93ee6dc… 2026-03-31 2026-04-17
HASH e10b1fa84f1d6481625f741b6989278… 2026-03-31 2026-04-17
DOMAIN calltan.com 2026-03-31 2026-04-17
DOMAIN callnrwise.com 2026-03-31 2026-04-17
HASH 617b67a8e1210e4fc87c92d1d1da45a… 2026-03-30 2026-04-17
HASH 92ff08773995ebc8d55ec4b8e1a225d… 2026-03-30 2026-04-17
HASH fcb81618bb15edfdedfb638b4c08a2a… 2026-03-30 2026-04-17
IPv4 142.11.206.73 2026-03-30 2026-04-17
IPv4 23.254.167.216 2025-01-14 2026-04-17
HASH e49c2732fb9861548208a78e72996b9… 2026-03-31 2026-04-03

Related Reports

« Back