STARDUST CHOLLIMA Likely Compromises Axios npm Package

2026-04-01 Crowd Strike

https://www.crowdstrike.com/en-us/blog/stardust-chollima-likely-compromises-axios-npm-package/

Thumbnail for STARDUST CHOLLIMA Likely Compromises Axios npm Package

CrowdStrike reports that a threat actor used stolen maintainer credentials on March 31, 2026 to compromise the widely used Axios npm package and deploy updated, platform-specific ZshBucket variants. The activity is attributed to STARDUST CHOLLIMA with moderate confidence based on ZshBucket use and infrastructure overlaps, though shared DPRK infrastructure with FAMOUS CHOLLIMA prevents higher confidence. The malicious chain targeted Linux, macOS, and Windows systems, with ZshBucket gaining a common JSON messaging protocol and commands for binary injection, script and command execution, filesystem enumeration, and implant termination. Infrastructure centered on sfrclak[.]com at 142.11.206[.]73, with related Hostwinds-hosted IPs overlapping prior STARDUST CHOLLIMA and FAMOUS CHOLLIMA activity. The incident matters because Axios is a high-volume open-source dependency and the updated malware suggests a DPRK-linked actor seeking to scale supply chain access, likely aligned with currency-generation objectives.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN sfrclak.com 2026-03-30 2026-04-20
IPv4 142.11.206.73 2026-03-30 2026-04-17
IPv4 23.254.167.216 2025-01-14 2026-04-17
IPv4 23.254.203.244 2025-06-20 2026-04-03
HASH c373706b3456c36e8baa0a3ee5aed35… 2026-04-01 2026-04-01

Related Actors

Related Reports

« Back