Axios npm Hijack 2026: Everything You Need to Know – IOCs, Impact & Remediation
2026-03-31 • SOCRadar •
https://socradar.io/blog/axios-npm-supply-chain-attack-2026-ciso-guide/
An attacker hijacked the npm account of Axios lead maintainer jasonsaayman and published malicious axios versions 1.14.1 and 0.30.4 on March 31, 2026. The poisoned releases added [email protected], whose postinstall script ran during npm install and downloaded a cross-platform RAT for Windows, macOS, or Linux. The campaign used a staged clean package, attacker-controlled ProtonMail accounts, a stolen long-lived npm access token, and direct npm publishing to bypass GitHub Actions, OIDC provenance, code review, and CI security controls. The excerpt lists sfrclak.com, 142.11.206.73, package hashes, platform-specific payload paths, and plain-crypto-js artifacts that defenders can use to scope exposed developer workstations, build servers, and CI/CD runners.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | sfrclak.com | 2026-03-30 | 2026-04-20 |
| [email protected] | 2026-03-30 | 2026-04-17 | |
| [email protected] | 2026-03-30 | 2026-04-17 | |
| URL | http://sfrclak.com:8000/6202033 | 2026-03-30 | 2026-04-17 |
| IPv4 | 142.11.206.73 | 2026-03-30 | 2026-04-17 |
| HASH | d6f3f62fd3b9f5432f5782b62d8cfd5… | 2026-03-30 | 2026-04-04 |
| HASH | 07d889e2dadce6f3910dcbc253317d2… | 2026-03-30 | 2026-04-04 |