Inside the Axios supply chain compromise - one RAT to rule them all
2026-04-01 • Elastic •
https://www.elastic.co/security-labs/axios-one-rat-to-rule-them-all
Elastic Security Labs analyzed the Axios npm supply-chain compromise in which a compromised maintainer account published backdoored [email protected] and [email protected] releases that pulled the malicious plain-crypto-js dependency. The dependency used an obfuscated postinstall dropper to contact sfrclak[.]com:8000 and deliver platform-specific RAT payloads for Windows, macOS, and Linux. The second-stage implants shared a common HTTP POST C2 protocol, Base64-encoded JSON messages, 60-second beaconing, an anomalous IE8/Windows XP user-agent, and commands for execution, directory enumeration, payload injection, and termination. The dropper also deleted setup.js and replaced package.json with a clean-looking copy, making lockfiles and telemetry important for incident response. The analysis matters because axios has very broad JavaScript ecosystem reach, so a short-lived malicious publish could expose many development and enterprise environments.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | sfrclak.com | 2026-03-30 | 2026-04-20 |
| HASH | 617b67a8e1210e4fc87c92d1d1da45a… | 2026-03-30 | 2026-04-17 |
| HASH | 92ff08773995ebc8d55ec4b8e1a225d… | 2026-03-30 | 2026-04-17 |
| HASH | fcb81618bb15edfdedfb638b4c08a2a… | 2026-03-30 | 2026-04-17 |
| [email protected] | 2026-03-30 | 2026-04-17 | |
| [email protected] | 2026-03-30 | 2026-04-17 | |
| URL | http://sfrclak.com:8000/6202033 | 2026-03-30 | 2026-04-17 |
| IPv4 | 142.11.206.73 | 2026-03-30 | 2026-04-17 |
| [email protected] | 2026-04-01 | 2026-04-01 |