Axios npm Backdoored: UNC1069 Deploys Cross-Platform RAT via Supply Chain Attack

2026-04-01 Cybersec Sentinel

https://cybersecsentinel.com/axios-npm-backdoored-unc1069-deploys-cross-platform-rat-via-supply-chain-attack/

Thumbnail for Axios npm Backdoored: UNC1069 Deploys Cross-Platform RAT via Supply Chain Attack

Malicious Axios npm releases 1.14.1 and 0.30.4 allegedly used a compromised maintainer account to add the hidden [email protected] dependency, causing npm install to execute a postinstall dropper. The excerpt attributes the operation to UNC1069, described as a financially motivated North Korea-nexus actor linked to BlueNoroff, and identifies SILKBELL as the dropper and WAVESHAPER.V2 as the cross-platform RAT. The infection chain delivered macOS, Windows, and Linux payloads from sfrclak[.]com:8000, with Windows persistence through %PROGRAMDATA%\system.bat and a Registry Run key, macOS ad-hoc code signing, and Linux deployment to /tmp/ld.py. The RAT supported command execution, additional payload deployment, filesystem reconnaissance, 60-second C2 beaconing, and cleanup steps that removed evidence of the postinstall chain. Infrastructure and account indicators included sfrclak[.]com, callnrwise[.]com, 142.11.206[.]73, ifstap[@]proton[.]me, and nrwise[@]proton[.]me.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN sfrclak.com 2026-03-30 2026-04-20
HASH e10b1fa84f1d6481625f741b6989278… 2026-03-31 2026-04-17
DOMAIN callnrwise.com 2026-03-31 2026-04-17
URL http://sfrclak.com:8000/6202033 2026-03-30 2026-04-17
IPv4 142.11.206.73 2026-03-30 2026-04-17
HASH d6f3f62fd3b9f5432f5782b62d8cfd5… 2026-03-30 2026-04-04
HASH 07d889e2dadce6f3910dcbc253317d2… 2026-03-30 2026-04-04
HASH 2553649f2322049666871cea80a5d0d… 2026-03-30 2026-04-04

Related Actors

Related Reports

« Back