Axios npm Supply Chain Attack - Cross-Platform RAT Deployed via Compromised Maintainer Account
2026-04-01 • Bitdefender •
Bitdefender attributes the axios incident to an unknown threat actor, not to any named state group, and describes a supply-chain compromise of the primary maintainer's npm account. The attacker published [email protected] and [email protected] with a hidden [email protected] dependency whose postinstall script downloaded platform-specific RAT payloads for Windows, macOS, and Linux. The Windows chain copied PowerShell to %PROGRAMDATA%\wt.exe, launched it with hidden execution-policy bypass flags, wrote %PROGRAMDATA%\system.bat, and persisted through an HKCU Run key named MicrosoftUpdate. The RAT contacted sfrclak[.]com:8000 and 142.11.206[.]73, enumerated user directories and host metadata, and supported remote PowerShell execution, process listing, directory browsing, binary injection, and self-termination. The report matters for defenders because developer machines and CI/CD systems that ran npm install during the exposure window may have exposed environment variables, cloud keys, SSH keys, npm tokens, and other build secrets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | sfrclak.com | 2026-03-30 | 2026-04-20 |
| [email protected] | 2026-03-30 | 2026-04-17 | |
| IPv4 | 142.11.206.73 | 2026-03-30 | 2026-04-17 |