Axios npm Supply Chain Compromise (2026-03-31) — Full RE + Dynamic Analysis + BlueNoroff Attribution

2026-03-31 N3mes1s

https://gist.github.com/N3mes1s/0c0fc7a0c23cdb5e1c8f66b208053ed6

Thumbnail for Axios npm Supply Chain Compromise (2026-03-31) — Full RE + Dynamic Analysis + BlueNoroff Attribution

The analysis attributes the March 2026 axios npm supply-chain compromise to BlueNoroff/Lazarus with high confidence, citing NukeSped classification, macWebT naming overlap with RustBucket webT, matching User-Agent behavior, Hostwinds infrastructure, and campaign TTP alignment. The attacker used a compromised axios maintainer account to publish [email protected] and [email protected] with a malicious [email protected] dependency that deployed Windows PowerShell, macOS Mach-O/C++, and Linux Python RAT payloads. The report reconstructs the C2 protocol and identifies sfrclak[.]com:8000 on 142.11.206.73, the /6202033 path, and callnrwise[.]com as related infrastructure, while noting some earlier domain-linkage claims were retracted. It also distinguishes likely downstream-victimized packages from attacker-controlled publishing accounts and frames the operation as part of a continuing DPRK npm and macOS targeting tempo.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN sfrclak.com 2026-03-30 2026-04-20
DOMAIN callnrwise.com 2026-03-31 2026-04-17
EMAIL [email protected] 2026-03-30 2026-04-17
EMAIL [email protected] 2026-03-30 2026-04-17
URL http://sfrclak.com:8000/6202033 2026-03-30 2026-04-17
IPv4 142.11.206.73 2026-03-30 2026-04-17
IPv4 23.254.167.216 2025-01-14 2026-04-17
HASH 656b9a2f4de6ed4909e157482860ab3d 2026-03-31 2026-03-31
HASH 1d9437ff1aa1e958ed34a0fb0313f206 2026-03-31 2026-03-31
HASH 773906b0efdefa24a7f2b8eb6985bf37 2026-03-31 2026-03-31
IPv4 144.172.89.231 2026-03-31 2026-03-31
IPv4 45.61.128.54 2026-03-31 2026-03-31

Related Actors

Related Reports

« Back