Supply Chain Attack on Axios Pulls Malicious Dependency from npm

2026-03-31 Socket

https://socket.dev/blog/axios-npm-package-compromised

Thumbnail for Supply Chain Attack on Axios Pulls Malicious Dependency from npm

Socket analyzed the axios supply-chain compromise in which [email protected] and [email protected] pulled the malicious [email protected] dependency through npm. The dependency’s postinstall hook ran setup.js, decoded obfuscated module names, commands, paths, and C2 details, then routed victims to macOS, Windows, or Linux payload delivery paths. The shared C2 endpoint was sfrclak[.]com:8000, with POST bodies mimicking npm-related traffic such as packages[.]npm[.]org/product0, product1, and product2. Socket and Elastic analysis of the macOS second stage described a C++ RAT that fingerprints the host, beacons every 60 seconds, enumerates directories, executes commands or AppleScript, deploys additional binaries, and can terminate itself. The report notes no observed evidence linking the activity to recently reported TeamPCP campaigns.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN sfrclak.com 2026-03-30 2026-04-20
URL http://sfrclak.com:8000/ 2026-03-31 2026-04-17
EMAIL [email protected] 2026-03-30 2026-04-17
URL http://sfrclak.com:8000/6202033 2026-03-30 2026-04-17
IPv4 142.11.206.73 2026-03-30 2026-04-17

Related Reports

« Back