Lazarus Group Poisons Axios: Inside the npm Supply Chain Attack
2026-03-31 • Threat Book •
https://threatbook.io/blog/lazarus-group-poisons-axios-inside-the-npm-supply-chain-attack
ThreatBook attributes the Axios npm supply-chain poisoning incident to Lazarus Group, citing long-term tracking, malware behavior, and infrastructure pivots. The attack used a hijacked Axios maintainer account to publish [email protected] and [email protected] with the malicious dependency [email protected], whose postinstall hook selected Linux, Windows, or macOS payloads from http://sfrclak.com:8000/6202033. ThreatBook’s macOS analysis describes /Library/Caches/com.apple.act.mond as a C++ trojan that collects host and process information, beacons with an old IE user agent, and supports process termination, shell and script execution, process injection, and directory listing. The report links the payload to WAVESHAPER-like tradecraft and lists sfrclak.com, 142.11.206.73, callnrwise.com, related IPs, payload hashes, and a Mandiant-style YARA rule as detection material.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | sfrclak.com | 2026-03-30 | 2026-04-20 |
| HASH | ed8560c1ac7ceb6983ba995124d5917… | 2026-03-31 | 2026-04-17 |
| HASH | f7d335205b8d7b20208fb3ef93ee6dc… | 2026-03-31 | 2026-04-17 |
| DOMAIN | callnrwise.com | 2026-03-31 | 2026-04-17 |
| HASH | 617b67a8e1210e4fc87c92d1d1da45a… | 2026-03-30 | 2026-04-17 |
| HASH | 92ff08773995ebc8d55ec4b8e1a225d… | 2026-03-30 | 2026-04-17 |
| HASH | fcb81618bb15edfdedfb638b4c08a2a… | 2026-03-30 | 2026-04-17 |
| URL | http://sfrclak.com:8000/6202033 | 2026-03-30 | 2026-04-17 |
| IPv4 | 142.11.206.73 | 2026-03-30 | 2026-04-17 |
| HASH | 4465bdeaddc8c049a67a3d5ec105b2f… | 2026-03-31 | 2026-04-01 |
| HASH | 506690fcbd10fbe6f2b85b49a1fffa9… | 2026-03-31 | 2026-04-01 |
| HASH | 5b5fbc627502c5797d97b206b6dcf53… | 2026-03-31 | 2026-04-01 |
| HASH | 46f5eea70d536f7affe40409d7aaa5f… | 2026-03-31 | 2026-03-31 |
| HASH | 8c8f5f095d65d3f33ce89a77dfbe84a… | 2026-03-31 | 2026-03-31 |
| IPv4 | 142.11.199.73 | 2026-03-31 | 2026-03-31 |
| IPv4 | 142.11.196.73 | 2026-03-31 | 2026-03-31 |
| YARA | G_Backdoor_WAVESHAPER_1 | 2026-02-10 | 2026-03-31 |
| HASH | c91725905b273e81e9cc6983a11c8d60 | 2026-02-10 | 2026-03-31 |