Axios npm Hijack 2026: Everything You Need to Know – IOCs, Impact & Remediation

2026-03-31 SOCRadar

https://socradar.io/blog/axios-npm-supply-chain-attack-2026-ciso-guide/

Thumbnail for Axios npm Hijack 2026: Everything You Need to Know – IOCs, Impact & Remediation

An attacker hijacked the npm account of Axios lead maintainer jasonsaayman and published malicious axios versions 1.14.1 and 0.30.4 on March 31, 2026. The poisoned releases added [email protected], whose postinstall script ran during npm install and downloaded a cross-platform RAT for Windows, macOS, or Linux. The campaign used a staged clean package, attacker-controlled ProtonMail accounts, a stolen long-lived npm access token, and direct npm publishing to bypass GitHub Actions, OIDC provenance, code review, and CI security controls. The excerpt lists sfrclak.com, 142.11.206.73, package hashes, platform-specific payload paths, and plain-crypto-js artifacts that defenders can use to scope exposed developer workstations, build servers, and CI/CD runners.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN sfrclak.com 2026-03-30 2026-04-20
EMAIL [email protected] 2026-03-30 2026-04-17
EMAIL [email protected] 2026-03-30 2026-04-17
URL http://sfrclak.com:8000/6202033 2026-03-30 2026-04-17
IPv4 142.11.206.73 2026-03-30 2026-04-17
HASH d6f3f62fd3b9f5432f5782b62d8cfd5… 2026-03-30 2026-04-04
HASH 07d889e2dadce6f3910dcbc253317d2… 2026-03-30 2026-04-04

Related Reports

« Back