Supply Chain Attack on Axios NPM Package via North Korean Threat Actors
2026-04-17 • Igloo •
https://www.igloopedia.com/345f216a-760c-8003-9c12-ecd7dfe4f1b6
Axios maintainer access was compromised to publish malicious [email protected] and [email protected] releases that added the typosquatted dependency [email protected] without changing the main Axios source. The malicious dependency used a postinstall hook to run an obfuscated Node.js dropper before application code executed, then branched by operating system to fetch macOS, Windows, or Linux payloads from sfrclak.com:8000. The macOS path downloaded a trojanized binary, the Windows path used VBScript and PowerShell, and the Linux path used a Python RAT launched with nohup, with the C2 distinguishing platforms through product-specific POST bodies. Google GTIG assessed the activity as likely UNC1069 or BlueNoroff, while Huntress, Elastic, and Volexity cited overlaps with BlueNoroff/RustBucket-style components, North Korea-linked backdoor structure, and prior campaign infrastructure such as calltan.com. The campaign is notable because it weaponized npm lifecycle scripts and dependency resolution in a high-download library, allowing compromise during installation before developers ran their own code.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | sfrclak.com | 2026-03-30 | 2026-04-20 |
| HASH | 9f914d42706fe215501044acd85a32d… | 2026-04-17 | 2026-04-17 |
| HASH | 0c0fc7a0c23cdb5e1c8f66b208053ed6 | 2026-04-17 | 2026-04-17 |
| HASH | 58401c195fe0a6204b42f5f90995ece… | 2026-03-31 | 2026-04-17 |
| HASH | ed8560c1ac7ceb6983ba995124d5917… | 2026-03-31 | 2026-04-17 |
| HASH | 59336a964f110c25c112bcc5adca709… | 2026-03-31 | 2026-04-17 |
| HASH | 5bb67e88846096f1f8d42a0f0350c9c… | 2026-03-31 | 2026-04-17 |
| HASH | f7d335205b8d7b20208fb3ef93ee6dc… | 2026-03-31 | 2026-04-17 |
| HASH | e10b1fa84f1d6481625f741b6989278… | 2026-03-31 | 2026-04-17 |
| URL | http://sfrclak.com:8000/ | 2026-03-31 | 2026-04-17 |
| DOMAIN | calltan.com | 2026-03-31 | 2026-04-17 |
| DOMAIN | callnrwise.com | 2026-03-31 | 2026-04-17 |
| HASH | 617b67a8e1210e4fc87c92d1d1da45a… | 2026-03-30 | 2026-04-17 |
| HASH | 92ff08773995ebc8d55ec4b8e1a225d… | 2026-03-30 | 2026-04-17 |
| HASH | fcb81618bb15edfdedfb638b4c08a2a… | 2026-03-30 | 2026-04-17 |
| [email protected] | 2026-03-30 | 2026-04-17 | |
| [email protected] | 2026-03-30 | 2026-04-17 | |
| URL | http://sfrclak.com:8000/6202033 | 2026-03-30 | 2026-04-17 |
| IPv4 | 142.11.206.73 | 2026-03-30 | 2026-04-17 |
| IPv4 | 23.254.167.216 | 2025-01-14 | 2026-04-17 |