Axios NPM supply chain incident

2026-04-03 Cisco Talos

https://blog.talosintelligence.com/axois-npm-supply-chain-incident/

Thumbnail for Axios NPM supply chain incident

Cisco Talos found that attackers published malicious Axios npm versions 1.14.1 and 0.30.4 on March 31, 2026, leaving the widely used JavaScript HTTP client exposed for about three hours. The modified packages introduced a fake dependency, plain-crypto-js, whose post-install script contacted 142[.]11[.]206[.]73 and delivered platform-specific payloads for macOS, Windows, and Linux. The payloads included a macOS binary named com.apple.act.mond, a Windows PowerShell chain using %PROGRAM DATA%\wt.exe, and a Linux Python backdoor with remote access trojan capabilities for information gathering and follow-on execution. Talos assessed that credentials present on systems that installed the malicious packages should be treated as compromised because the actor gained both exfiltration and remote management capabilities.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN sfrclak.com 2026-03-30 2026-04-20
HASH ed8560c1ac7ceb6983ba995124d5917… 2026-03-31 2026-04-17
HASH e10b1fa84f1d6481625f741b6989278… 2026-03-31 2026-04-17
HASH 617b67a8e1210e4fc87c92d1d1da45a… 2026-03-30 2026-04-17
HASH 92ff08773995ebc8d55ec4b8e1a225d… 2026-03-30 2026-04-17
HASH fcb81618bb15edfdedfb638b4c08a2a… 2026-03-30 2026-04-17
IPv4 142.11.206.73 2026-03-30 2026-04-17

Related Reports

« Back