From Axios NPM Supply Chain Attack to Tracking DPRK’s BlueNoroff
2026-04-03 • DCSO •
DCSO analyzed public indicators from the axios npm compromise and found infrastructure overlaps suggesting possible connections to the DPRK-linked BlueNoroff cluster. The attacker used newly created Proton Mail accounts, compromised the axios maintainer account, and published malicious releases that executed setup.js through a postinstall function. Pivoting from reported C2 indicators, DCSO identified shared Express server behavior, port 8000 exposure, a weak ETag pattern, Hostwinds-hosted infrastructure, and a previously unreported IP address, 23.254.203[.]244. The report is careful that the TTP overlaps are not highly specific, but notes that the financial motivation, Hostwinds infrastructure history, curl ingress transfer, AppleScript, and Unix shell use make the BlueNoroff connection worth further investigation.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | sfrclak.com | 2026-03-30 | 2026-04-20 |
| [email protected] | 2026-03-30 | 2026-04-17 | |
| [email protected] | 2026-03-30 | 2026-04-17 | |
| URL | http://sfrclak.com:8000/6202033 | 2026-03-30 | 2026-04-17 |
| IPv4 | 142.11.206.73 | 2026-03-30 | 2026-04-17 |
| IPv4 | 23.254.167.216 | 2025-01-14 | 2026-04-17 |
| URL | http://sfrclak.com | 2026-04-01 | 2026-04-03 |
| URL | http://sfrclak.com:8000 | 2026-04-01 | 2026-04-03 |
| IPv4 | 23.254.203.244 | 2025-06-20 | 2026-04-03 |