Supply Chain Attack on Axios NPM Package via North Korean Threat Actors

2026-04-17 Igloo

https://www.igloopedia.com/345f216a-760c-8003-9c12-ecd7dfe4f1b6

Thumbnail for Supply Chain Attack on Axios NPM Package via North Korean Threat Actors

Axios maintainer access was compromised to publish malicious [email protected] and [email protected] releases that added the typosquatted dependency [email protected] without changing the main Axios source. The malicious dependency used a postinstall hook to run an obfuscated Node.js dropper before application code executed, then branched by operating system to fetch macOS, Windows, or Linux payloads from sfrclak.com:8000. The macOS path downloaded a trojanized binary, the Windows path used VBScript and PowerShell, and the Linux path used a Python RAT launched with nohup, with the C2 distinguishing platforms through product-specific POST bodies. Google GTIG assessed the activity as likely UNC1069 or BlueNoroff, while Huntress, Elastic, and Volexity cited overlaps with BlueNoroff/RustBucket-style components, North Korea-linked backdoor structure, and prior campaign infrastructure such as calltan.com. The campaign is notable because it weaponized npm lifecycle scripts and dependency resolution in a high-download library, allowing compromise during installation before developers ran their own code.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN sfrclak.com 2026-03-30 2026-04-20
HASH 9f914d42706fe215501044acd85a32d… 2026-04-17 2026-04-17
HASH 0c0fc7a0c23cdb5e1c8f66b208053ed6 2026-04-17 2026-04-17
HASH 58401c195fe0a6204b42f5f90995ece… 2026-03-31 2026-04-17
HASH ed8560c1ac7ceb6983ba995124d5917… 2026-03-31 2026-04-17
HASH 59336a964f110c25c112bcc5adca709… 2026-03-31 2026-04-17
HASH 5bb67e88846096f1f8d42a0f0350c9c… 2026-03-31 2026-04-17
HASH f7d335205b8d7b20208fb3ef93ee6dc… 2026-03-31 2026-04-17
HASH e10b1fa84f1d6481625f741b6989278… 2026-03-31 2026-04-17
URL http://sfrclak.com:8000/ 2026-03-31 2026-04-17
DOMAIN calltan.com 2026-03-31 2026-04-17
DOMAIN callnrwise.com 2026-03-31 2026-04-17
HASH 617b67a8e1210e4fc87c92d1d1da45a… 2026-03-30 2026-04-17
HASH 92ff08773995ebc8d55ec4b8e1a225d… 2026-03-30 2026-04-17
HASH fcb81618bb15edfdedfb638b4c08a2a… 2026-03-30 2026-04-17
EMAIL [email protected] 2026-03-30 2026-04-17
EMAIL [email protected] 2026-03-30 2026-04-17
URL http://sfrclak.com:8000/6202033 2026-03-30 2026-04-17
IPv4 142.11.206.73 2026-03-30 2026-04-17
IPv4 23.254.167.216 2025-01-14 2026-04-17

Related Reports

« Back