Axios npm Supply Chain Compromise (2026-03-31) — Full RE + Dynamic Analysis + BlueNoroff Attribution
2026-03-31 • N3mes1s •
https://gist.github.com/N3mes1s/0c0fc7a0c23cdb5e1c8f66b208053ed6
The analysis attributes the March 2026 axios npm supply-chain compromise to BlueNoroff/Lazarus with high confidence, citing NukeSped classification, macWebT naming overlap with RustBucket webT, matching User-Agent behavior, Hostwinds infrastructure, and campaign TTP alignment. The attacker used a compromised axios maintainer account to publish [email protected] and [email protected] with a malicious [email protected] dependency that deployed Windows PowerShell, macOS Mach-O/C++, and Linux Python RAT payloads. The report reconstructs the C2 protocol and identifies sfrclak[.]com:8000 on 142.11.206.73, the /6202033 path, and callnrwise[.]com as related infrastructure, while noting some earlier domain-linkage claims were retracted. It also distinguishes likely downstream-victimized packages from attacker-controlled publishing accounts and frames the operation as part of a continuing DPRK npm and macOS targeting tempo.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | sfrclak.com | 2026-03-30 | 2026-04-20 |
| DOMAIN | callnrwise.com | 2026-03-31 | 2026-04-17 |
| [email protected] | 2026-03-30 | 2026-04-17 | |
| [email protected] | 2026-03-30 | 2026-04-17 | |
| URL | http://sfrclak.com:8000/6202033 | 2026-03-30 | 2026-04-17 |
| IPv4 | 142.11.206.73 | 2026-03-30 | 2026-04-17 |
| IPv4 | 23.254.167.216 | 2025-01-14 | 2026-04-17 |
| HASH | 656b9a2f4de6ed4909e157482860ab3d | 2026-03-31 | 2026-03-31 |
| HASH | 1d9437ff1aa1e958ed34a0fb0313f206 | 2026-03-31 | 2026-03-31 |
| HASH | 773906b0efdefa24a7f2b8eb6985bf37 | 2026-03-31 | 2026-03-31 |
| IPv4 | 144.172.89.231 | 2026-03-31 | 2026-03-31 |
| IPv4 | 45.61.128.54 | 2026-03-31 | 2026-03-31 |