Compromised axios npm package delivers cross-platform RAT

2026-03-31 Datadog

https://securitylabs.datadoghq.com/articles/axios-npm-supply-chain-compromise/

Thumbnail for Compromised axios npm package delivers cross-platform RAT

Datadog analyzes the March 31, 2026 axios npm compromise in which a hijacked maintainer account published [email protected] and [email protected] with a new dependency on plain-crypto-js. The typosquatted package cloned crypto-js but added a postinstall setup.js script that decoded obfuscated strings, contacted http://sfrclak.com:8000/6202033, and retrieved platform-specific RAT payloads for macOS, Windows, and Linux. Registry metadata showed the malicious releases were published directly from the compromised jasonsaayman account with the attacker email [email protected], unlike the legitimate OIDC trusted publishing path used for [email protected]. Datadog notes the packages were available for about three hours, identifies filesystem and network indicators, and assesses with reasonable confidence that the activity is unrelated to the recent TeamPCP supply-chain campaign.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN sfrclak.com 2026-03-30 2026-04-20
HASH 617b67a8e1210e4fc87c92d1d1da45a… 2026-03-30 2026-04-17
HASH 92ff08773995ebc8d55ec4b8e1a225d… 2026-03-30 2026-04-17
HASH fcb81618bb15edfdedfb638b4c08a2a… 2026-03-30 2026-04-17
EMAIL [email protected] 2026-03-30 2026-04-17
EMAIL [email protected] 2026-03-30 2026-04-17
URL http://sfrclak.com:8000/6202033 2026-03-30 2026-04-17
IPv4 142.11.206.73 2026-03-30 2026-04-17

Related Reports

« Back