From Axios NPM Supply Chain Attack to Tracking DPRK’s BlueNoroff

2026-04-03 DCSO

https://medium.com/@DCSO_CyTec/from-axios-npm-supply-chain-attack-to-tracking-dprks-bluenoroff-c9080c9b4ce3

Thumbnail for From Axios NPM Supply Chain Attack to Tracking DPRK’s BlueNoroff

DCSO analyzed public indicators from the axios npm compromise and found infrastructure overlaps suggesting possible connections to the DPRK-linked BlueNoroff cluster. The attacker used newly created Proton Mail accounts, compromised the axios maintainer account, and published malicious releases that executed setup.js through a postinstall function. Pivoting from reported C2 indicators, DCSO identified shared Express server behavior, port 8000 exposure, a weak ETag pattern, Hostwinds-hosted infrastructure, and a previously unreported IP address, 23.254.203[.]244. The report is careful that the TTP overlaps are not highly specific, but notes that the financial motivation, Hostwinds infrastructure history, curl ingress transfer, AppleScript, and Unix shell use make the BlueNoroff connection worth further investigation.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN sfrclak.com 2026-03-30 2026-04-20
EMAIL [email protected] 2026-03-30 2026-04-17
EMAIL [email protected] 2026-03-30 2026-04-17
URL http://sfrclak.com:8000/6202033 2026-03-30 2026-04-17
IPv4 142.11.206.73 2026-03-30 2026-04-17
IPv4 23.254.167.216 2025-01-14 2026-04-17
URL http://sfrclak.com 2026-04-01 2026-04-03
URL http://sfrclak.com:8000 2026-04-01 2026-04-03
IPv4 23.254.203.244 2025-06-20 2026-04-03

Related Actors

Related Reports

« Back