Lazarus Group Poisons Axios: Inside the npm Supply Chain Attack

2026-03-31 Threat Book

https://threatbook.io/blog/lazarus-group-poisons-axios-inside-the-npm-supply-chain-attack

Thumbnail for Lazarus Group Poisons Axios: Inside the npm Supply Chain Attack

ThreatBook attributes the Axios npm supply-chain poisoning incident to Lazarus Group, citing long-term tracking, malware behavior, and infrastructure pivots. The attack used a hijacked Axios maintainer account to publish [email protected] and [email protected] with the malicious dependency [email protected], whose postinstall hook selected Linux, Windows, or macOS payloads from http://sfrclak.com:8000/6202033. ThreatBook’s macOS analysis describes /Library/Caches/com.apple.act.mond as a C++ trojan that collects host and process information, beacons with an old IE user agent, and supports process termination, shell and script execution, process injection, and directory listing. The report links the payload to WAVESHAPER-like tradecraft and lists sfrclak.com, 142.11.206.73, callnrwise.com, related IPs, payload hashes, and a Mandiant-style YARA rule as detection material.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN sfrclak.com 2026-03-30 2026-04-20
HASH ed8560c1ac7ceb6983ba995124d5917… 2026-03-31 2026-04-17
HASH f7d335205b8d7b20208fb3ef93ee6dc… 2026-03-31 2026-04-17
DOMAIN callnrwise.com 2026-03-31 2026-04-17
HASH 617b67a8e1210e4fc87c92d1d1da45a… 2026-03-30 2026-04-17
HASH 92ff08773995ebc8d55ec4b8e1a225d… 2026-03-30 2026-04-17
HASH fcb81618bb15edfdedfb638b4c08a2a… 2026-03-30 2026-04-17
URL http://sfrclak.com:8000/6202033 2026-03-30 2026-04-17
IPv4 142.11.206.73 2026-03-30 2026-04-17
HASH 4465bdeaddc8c049a67a3d5ec105b2f… 2026-03-31 2026-04-01
HASH 506690fcbd10fbe6f2b85b49a1fffa9… 2026-03-31 2026-04-01
HASH 5b5fbc627502c5797d97b206b6dcf53… 2026-03-31 2026-04-01
HASH 46f5eea70d536f7affe40409d7aaa5f… 2026-03-31 2026-03-31
HASH 8c8f5f095d65d3f33ce89a77dfbe84a… 2026-03-31 2026-03-31
IPv4 142.11.199.73 2026-03-31 2026-03-31
IPv4 142.11.196.73 2026-03-31 2026-03-31
YARA G_Backdoor_WAVESHAPER_1 2026-02-10 2026-03-31
HASH c91725905b273e81e9cc6983a11c8d60 2026-02-10 2026-03-31

Related Actors

Related Reports

« Back