Axios NPM Package Supply Chain Compromise Leads to RAT Deployment

2026-04-09 Levelblue

https://www.levelblue.com/blogs/spiderlabs-blog/axios-npm-package-supply-chain-compromise-leads-to-rat-deployment

Thumbnail for Axios NPM Package Supply Chain Compromise Leads to RAT Deployment

Malicious Axios npm versions `[email protected]` and `[email protected]` were observed in a customer environment after attackers abused npm lifecycle execution through a hidden dependency. The postinstall chain launched shell and PowerShell activity, downloaded a secondary payload from attacker infrastructure, and led to suspected RAT deployment on developer or CI/CD systems. LevelBlue reported detections for abnormal process chains, renamed PowerShell activity, and outbound C2 communication, and recommended isolating and rebuilding affected hosts, rotating credentials, auditing builds, and disabling npm lifecycle scripts where feasible.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN sfrclak.com 2026-03-30 2026-04-20
HASH e10b1fa84f1d6481625f741b6989278… 2026-03-31 2026-04-17
HASH 617b67a8e1210e4fc87c92d1d1da45a… 2026-03-30 2026-04-17
URL http://sfrclak.com:8000/6202033 2026-03-30 2026-04-17
IPv4 142.11.206.73 2026-03-30 2026-04-17

Related Reports

« Back