STARDUST CHOLLIMA Likely Compromises Axios npm Package
2026-04-01 • Crowd Strike •
https://www.crowdstrike.com/en-us/blog/stardust-chollima-likely-compromises-axios-npm-package/
CrowdStrike reports that a threat actor used stolen maintainer credentials on March 31, 2026 to compromise the widely used Axios npm package and deploy updated, platform-specific ZshBucket variants. The activity is attributed to STARDUST CHOLLIMA with moderate confidence based on ZshBucket use and infrastructure overlaps, though shared DPRK infrastructure with FAMOUS CHOLLIMA prevents higher confidence. The malicious chain targeted Linux, macOS, and Windows systems, with ZshBucket gaining a common JSON messaging protocol and commands for binary injection, script and command execution, filesystem enumeration, and implant termination. Infrastructure centered on sfrclak[.]com at 142.11.206[.]73, with related Hostwinds-hosted IPs overlapping prior STARDUST CHOLLIMA and FAMOUS CHOLLIMA activity. The incident matters because Axios is a high-volume open-source dependency and the updated malware suggests a DPRK-linked actor seeking to scale supply chain access, likely aligned with currency-generation objectives.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | sfrclak.com | 2026-03-30 | 2026-04-20 |
| IPv4 | 142.11.206.73 | 2026-03-30 | 2026-04-17 |
| IPv4 | 23.254.167.216 | 2025-01-14 | 2026-04-17 |
| IPv4 | 23.254.203.244 | 2025-06-20 | 2026-04-03 |
| HASH | c373706b3456c36e8baa0a3ee5aed35… | 2026-04-01 | 2026-04-01 |