Inside the Axios supply chain compromise - one RAT to rule them all

2026-04-01 Elastic

https://www.elastic.co/security-labs/axios-one-rat-to-rule-them-all

Thumbnail for Inside the Axios supply chain compromise - one RAT to rule them all

Elastic Security Labs analyzed the Axios npm supply-chain compromise in which a compromised maintainer account published backdoored [email protected] and [email protected] releases that pulled the malicious plain-crypto-js dependency. The dependency used an obfuscated postinstall dropper to contact sfrclak[.]com:8000 and deliver platform-specific RAT payloads for Windows, macOS, and Linux. The second-stage implants shared a common HTTP POST C2 protocol, Base64-encoded JSON messages, 60-second beaconing, an anomalous IE8/Windows XP user-agent, and commands for execution, directory enumeration, payload injection, and termination. The dropper also deleted setup.js and replaced package.json with a clean-looking copy, making lockfiles and telemetry important for incident response. The analysis matters because axios has very broad JavaScript ecosystem reach, so a short-lived malicious publish could expose many development and enterprise environments.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN sfrclak.com 2026-03-30 2026-04-20
HASH 617b67a8e1210e4fc87c92d1d1da45a… 2026-03-30 2026-04-17
HASH 92ff08773995ebc8d55ec4b8e1a225d… 2026-03-30 2026-04-17
HASH fcb81618bb15edfdedfb638b4c08a2a… 2026-03-30 2026-04-17
EMAIL [email protected] 2026-03-30 2026-04-17
EMAIL [email protected] 2026-03-30 2026-04-17
URL http://sfrclak.com:8000/6202033 2026-03-30 2026-04-17
IPv4 142.11.206.73 2026-03-30 2026-04-17
EMAIL [email protected] 2026-04-01 2026-04-01

Related Reports

« Back