Breaking Down the Axios Supply Chain Attack: Dropper, Cross-Platform RATs, and BlueNoroff/TA444

2026-04-01 Hunt.io

https://hunt.io/blog/axios-supply-chain-attack-ta444-bluenoroff

Thumbnail for Breaking Down the Axios Supply Chain Attack: Dropper, Cross-Platform RATs, and BlueNoroff/TA444

Hunt.io traces the Axios npm compromise to a staged operation involving takeover of maintainer jasonsaayman's npm account, publication of malicious axios releases, and weaponization of [email protected] as a postinstall dropper. The dropper hid its strings with XOR and reversed Base64, detected the victim OS, and pulled platform-specific RATs from sfrclak.com:8000 at 142.11.206.73 using product identifiers for macOS, Windows, and Linux payloads. The RATs shared commands for killing the implant, dropping binaries, running scripts, and browsing files; Windows also used a renamed PowerShell binary, hidden VBScript execution, execution-policy bypass, and Registry Run-key persistence. Hunt.io links the C2 infrastructure to TA444/BlueNoroff through a shared ETag with a known JustJoin server, Hostwinds AS54290 subnet overlap, and NukeSped malware classification, making the supply-chain event relevant to DPRK-linked intrusion tracking.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN sfrclak.com 2026-03-30 2026-04-20
HASH f7d335205b8d7b20208fb3ef93ee6dc… 2026-03-31 2026-04-17
HASH e10b1fa84f1d6481625f741b6989278… 2026-03-31 2026-04-17
URL http://sfrclak.com:8000/ 2026-03-31 2026-04-17
HASH 617b67a8e1210e4fc87c92d1d1da45a… 2026-03-30 2026-04-17
HASH fcb81618bb15edfdedfb638b4c08a2a… 2026-03-30 2026-04-17
EMAIL [email protected] 2026-03-30 2026-04-17
EMAIL [email protected] 2026-03-30 2026-04-17
URL http://sfrclak.com:8000/6202033 2026-03-30 2026-04-17
IPv4 142.11.206.73 2026-03-30 2026-04-17
IPv4 23.254.167.216 2025-01-14 2026-04-17
HASH d6f3f62fd3b9f5432f5782b62d8cfd5… 2026-03-30 2026-04-04
HASH 07d889e2dadce6f3910dcbc253317d2… 2026-03-30 2026-04-04
HASH 506690fcbd10fbe6f2b85b49a1fffa9… 2026-03-31 2026-04-01
HASH e1f6b7f621a391a9d26e9a196974f3e… 2025-01-14 2026-04-01
IPv4 108.174.194.196 2025-01-14 2026-04-01
IPv4 108.174.194.44 2025-01-14 2026-04-01

Related Actors

Related Reports

« Back