Axios npm Supply Chain Attack - Cross-Platform RAT Deployed via Compromised Maintainer Account

2026-04-01 Bitdefender

https://www.bitdefender.com/en-us/blog/businessinsights/technical-advisory-axios-npm-supply-chain-attack-cross-platform-rat-deployed-compromised-account

Thumbnail for Axios npm Supply Chain Attack - Cross-Platform RAT Deployed via Compromised Maintainer Account

Bitdefender attributes the axios incident to an unknown threat actor, not to any named state group, and describes a supply-chain compromise of the primary maintainer's npm account. The attacker published [email protected] and [email protected] with a hidden [email protected] dependency whose postinstall script downloaded platform-specific RAT payloads for Windows, macOS, and Linux. The Windows chain copied PowerShell to %PROGRAMDATA%\wt.exe, launched it with hidden execution-policy bypass flags, wrote %PROGRAMDATA%\system.bat, and persisted through an HKCU Run key named MicrosoftUpdate. The RAT contacted sfrclak[.]com:8000 and 142.11.206[.]73, enumerated user directories and host metadata, and supported remote PowerShell execution, process listing, directory browsing, binary injection, and self-termination. The report matters for defenders because developer machines and CI/CD systems that ran npm install during the exposure window may have exposed environment variables, cloud keys, SSH keys, npm tokens, and other build secrets.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN sfrclak.com 2026-03-30 2026-04-20
EMAIL [email protected] 2026-03-30 2026-04-17
IPv4 142.11.206.73 2026-03-30 2026-04-17

Related Reports

« Back