Axios NPM Package Supply Chain Compromise Leads to RAT Deployment
2026-04-09 • Levelblue •
Malicious Axios npm versions `[email protected]` and `[email protected]` were observed in a customer environment after attackers abused npm lifecycle execution through a hidden dependency. The postinstall chain launched shell and PowerShell activity, downloaded a secondary payload from attacker infrastructure, and led to suspected RAT deployment on developer or CI/CD systems. LevelBlue reported detections for abnormal process chains, renamed PowerShell activity, and outbound C2 communication, and recommended isolating and rebuilding affected hosts, rotating credentials, auditing builds, and disabling npm lifecycle scripts where feasible.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | sfrclak.com | 2026-03-30 | 2026-04-20 |
| HASH | e10b1fa84f1d6481625f741b6989278… | 2026-03-31 | 2026-04-17 |
| HASH | 617b67a8e1210e4fc87c92d1d1da45a… | 2026-03-30 | 2026-04-17 |
| URL | http://sfrclak.com:8000/6202033 | 2026-03-30 | 2026-04-17 |
| IPv4 | 142.11.206.73 | 2026-03-30 | 2026-04-17 |