Axios npm package compromised to deploy malware

2026-03-31 Sophos

https://www.sophos.com/en-us/blog/axios-npm-package-compromised-to-deploy-malware

Thumbnail for Axios npm package compromised to deploy malware

Sophos CTU reported that Axios versions 1.14.1 and 0.30.4 were compromised after an apparent npm maintainer account takeover and used to deploy a cross-platform RAT. The malicious dependency executed during installation, retrieved platform-specific second-stage payloads from C2 infrastructure, and attempted to remove artifacts and replace package metadata with a clean version. Sophos telemetry first detected related activity around 00:45 UTC on March 31, 2026, with macOS, Windows, and Linux systems affected but no confirmed follow-on actor activity at publication time. CTU assessed it was highly likely NICKEL GLADSTONE, a North Korea-linked revenue-focused state-sponsored group, was responsible based on matching forensic metadata, C2 patterns, and links to malware exclusively used by the group.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN sfrclak.com 2026-03-30 2026-04-20
HASH 58401c195fe0a6204b42f5f90995ece… 2026-03-31 2026-04-17
HASH 59336a964f110c25c112bcc5adca709… 2026-03-31 2026-04-17
HASH 5bb67e88846096f1f8d42a0f0350c9c… 2026-03-31 2026-04-17
HASH f7d335205b8d7b20208fb3ef93ee6dc… 2026-03-31 2026-04-17
HASH e10b1fa84f1d6481625f741b6989278… 2026-03-31 2026-04-17
DOMAIN callnrwise.com 2026-03-31 2026-04-17
HASH 617b67a8e1210e4fc87c92d1d1da45a… 2026-03-30 2026-04-17
HASH 92ff08773995ebc8d55ec4b8e1a225d… 2026-03-30 2026-04-17
HASH fcb81618bb15edfdedfb638b4c08a2a… 2026-03-30 2026-04-17
EMAIL [email protected] 2026-03-30 2026-04-17
EMAIL [email protected] 2026-03-30 2026-04-17
URL http://sfrclak.com:8000/6202033 2026-03-30 2026-04-17
IPv4 142.11.206.73 2026-03-30 2026-04-17
HASH d6f3f62fd3b9f5432f5782b62d8cfd5… 2026-03-30 2026-04-04
HASH 07d889e2dadce6f3910dcbc253317d2… 2026-03-30 2026-04-04
HASH 2553649f2322049666871cea80a5d0d… 2026-03-30 2026-04-04
HASH e49c2732fb9861548208a78e72996b9… 2026-03-31 2026-04-03
HASH 7658962ae060a222c0058cd4e979bfa1 2026-03-31 2026-04-01
HASH 04e3073b3cd5c5bfcde6f575ecf6e8c1 2026-03-31 2026-04-01
HASH 089e2872016f75a5223b5e02c184dfec 2026-03-31 2026-04-01
HASH 13ab317c5dcab9af2d1bdb22118b9f0… 2026-03-31 2026-03-31
HASH a90c26e7cbb3440ac1cad75cf351cbe… 2026-03-31 2026-03-31
HASH 21d2470cae072cf2d027d473d168158c 2026-03-31 2026-03-31
HASH db7f4c82c732e8b107492cae419740ab 2026-03-31 2026-03-31
HASH ae39c4c550ad656622736134035f17c… 2026-03-31 2026-03-31
HASH 7a9ddef00f69477b96252ca234fcbeeb 2026-03-31 2026-03-31
HASH 8c782b59a786f18520673e8d669e3b0a 2026-03-31 2026-03-31
HASH 978407431d75885228e077691354399… 2026-03-31 2026-03-31
HASH 59faac136680104948e083b3b67a70a… 2026-03-31 2026-03-31
HASH b0e0f12f1be57dc67fa375e860cedd1… 2026-03-31 2026-03-31
HASH 9663665850cdd8fe12e30a671e5c4e6f 2026-03-31 2026-03-31

Related Reports

« Back