Compromised axios npm package delivers cross-platform RAT
2026-03-31 • Datadog •
https://securitylabs.datadoghq.com/articles/axios-npm-supply-chain-compromise/
Datadog analyzes the March 31, 2026 axios npm compromise in which a hijacked maintainer account published [email protected] and [email protected] with a new dependency on plain-crypto-js. The typosquatted package cloned crypto-js but added a postinstall setup.js script that decoded obfuscated strings, contacted http://sfrclak.com:8000/6202033, and retrieved platform-specific RAT payloads for macOS, Windows, and Linux. Registry metadata showed the malicious releases were published directly from the compromised jasonsaayman account with the attacker email [email protected], unlike the legitimate OIDC trusted publishing path used for [email protected]. Datadog notes the packages were available for about three hours, identifies filesystem and network indicators, and assesses with reasonable confidence that the activity is unrelated to the recent TeamPCP supply-chain campaign.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | sfrclak.com | 2026-03-30 | 2026-04-20 |
| HASH | 617b67a8e1210e4fc87c92d1d1da45a… | 2026-03-30 | 2026-04-17 |
| HASH | 92ff08773995ebc8d55ec4b8e1a225d… | 2026-03-30 | 2026-04-17 |
| HASH | fcb81618bb15edfdedfb638b4c08a2a… | 2026-03-30 | 2026-04-17 |
| [email protected] | 2026-03-30 | 2026-04-17 | |
| [email protected] | 2026-03-30 | 2026-04-17 | |
| URL | http://sfrclak.com:8000/6202033 | 2026-03-30 | 2026-04-17 |
| IPv4 | 142.11.206.73 | 2026-03-30 | 2026-04-17 |