Breaking Down the Axios Supply Chain Attack: Dropper, Cross-Platform RATs, and BlueNoroff/TA444
2026-04-01 • Hunt.io •
https://hunt.io/blog/axios-supply-chain-attack-ta444-bluenoroff
Hunt.io traces the Axios npm compromise to a staged operation involving takeover of maintainer jasonsaayman's npm account, publication of malicious axios releases, and weaponization of [email protected] as a postinstall dropper. The dropper hid its strings with XOR and reversed Base64, detected the victim OS, and pulled platform-specific RATs from sfrclak.com:8000 at 142.11.206.73 using product identifiers for macOS, Windows, and Linux payloads. The RATs shared commands for killing the implant, dropping binaries, running scripts, and browsing files; Windows also used a renamed PowerShell binary, hidden VBScript execution, execution-policy bypass, and Registry Run-key persistence. Hunt.io links the C2 infrastructure to TA444/BlueNoroff through a shared ETag with a known JustJoin server, Hostwinds AS54290 subnet overlap, and NukeSped malware classification, making the supply-chain event relevant to DPRK-linked intrusion tracking.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | sfrclak.com | 2026-03-30 | 2026-04-20 |
| HASH | f7d335205b8d7b20208fb3ef93ee6dc… | 2026-03-31 | 2026-04-17 |
| HASH | e10b1fa84f1d6481625f741b6989278… | 2026-03-31 | 2026-04-17 |
| URL | http://sfrclak.com:8000/ | 2026-03-31 | 2026-04-17 |
| HASH | 617b67a8e1210e4fc87c92d1d1da45a… | 2026-03-30 | 2026-04-17 |
| HASH | fcb81618bb15edfdedfb638b4c08a2a… | 2026-03-30 | 2026-04-17 |
| [email protected] | 2026-03-30 | 2026-04-17 | |
| [email protected] | 2026-03-30 | 2026-04-17 | |
| URL | http://sfrclak.com:8000/6202033 | 2026-03-30 | 2026-04-17 |
| IPv4 | 142.11.206.73 | 2026-03-30 | 2026-04-17 |
| IPv4 | 23.254.167.216 | 2025-01-14 | 2026-04-17 |
| HASH | d6f3f62fd3b9f5432f5782b62d8cfd5… | 2026-03-30 | 2026-04-04 |
| HASH | 07d889e2dadce6f3910dcbc253317d2… | 2026-03-30 | 2026-04-04 |
| HASH | 506690fcbd10fbe6f2b85b49a1fffa9… | 2026-03-31 | 2026-04-01 |
| HASH | e1f6b7f621a391a9d26e9a196974f3e… | 2025-01-14 | 2026-04-01 |
| IPv4 | 108.174.194.196 | 2025-01-14 | 2026-04-01 |
| IPv4 | 108.174.194.44 | 2025-01-14 | 2026-04-01 |