Axios NPM supply chain incident
2026-04-03 • Cisco Talos •
https://blog.talosintelligence.com/axois-npm-supply-chain-incident/
Cisco Talos found that attackers published malicious Axios npm versions 1.14.1 and 0.30.4 on March 31, 2026, leaving the widely used JavaScript HTTP client exposed for about three hours. The modified packages introduced a fake dependency, plain-crypto-js, whose post-install script contacted 142[.]11[.]206[.]73 and delivered platform-specific payloads for macOS, Windows, and Linux. The payloads included a macOS binary named com.apple.act.mond, a Windows PowerShell chain using %PROGRAM DATA%\wt.exe, and a Linux Python backdoor with remote access trojan capabilities for information gathering and follow-on execution. Talos assessed that credentials present on systems that installed the malicious packages should be treated as compromised because the actor gained both exfiltration and remote management capabilities.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | sfrclak.com | 2026-03-30 | 2026-04-20 |
| HASH | ed8560c1ac7ceb6983ba995124d5917… | 2026-03-31 | 2026-04-17 |
| HASH | e10b1fa84f1d6481625f741b6989278… | 2026-03-31 | 2026-04-17 |
| HASH | 617b67a8e1210e4fc87c92d1d1da45a… | 2026-03-30 | 2026-04-17 |
| HASH | 92ff08773995ebc8d55ec4b8e1a225d… | 2026-03-30 | 2026-04-17 |
| HASH | fcb81618bb15edfdedfb638b4c08a2a… | 2026-03-30 | 2026-04-17 |
| IPv4 | 142.11.206.73 | 2026-03-30 | 2026-04-17 |