Supply Chain Compromise of axios npm Package

2026-03-31 Huntress

https://www.huntress.com/blog/supply-chain-compromise-axios-npm-package

Thumbnail for Supply Chain Compromise of axios npm Package

Huntress observed active exploitation of the axios npm supply-chain compromise, with malicious [email protected] and [email protected] delivering a cross-platform RAT through the [email protected] postinstall hook. The update notes multiple indicators pointing to North Korean state-sponsored activity, including overlaps between the macOS payload and a DPRK-linked backdoor, the macWebT project name’s connection to BlueNoroff’s RustBucket webT module, and Google Threat Intelligence Group attribution to UNC1069. Huntress reported at least 135 monitored endpoints contacting attacker C2 during the exposure window and documented Windows tradecraft including VBScript staging, a copied powershell.exe masquerading as %PROGRAMDATA%\wt.exe, and persistence via system.bat plus an HKCU Run key. The report advises treating affected hosts as fully compromised because the RAT supported credential theft, data exfiltration, reconnaissance, and follow-on execution even after the npm packages and C2 infrastructure were removed.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN sfrclak.com 2026-03-30 2026-04-20
HASH f7d335205b8d7b20208fb3ef93ee6dc… 2026-03-31 2026-04-17
DOMAIN calltan.com 2026-03-31 2026-04-17
DOMAIN callnrwise.com 2026-03-31 2026-04-17
HASH 617b67a8e1210e4fc87c92d1d1da45a… 2026-03-30 2026-04-17
HASH 92ff08773995ebc8d55ec4b8e1a225d… 2026-03-30 2026-04-17
HASH fcb81618bb15edfdedfb638b4c08a2a… 2026-03-30 2026-04-17
EMAIL [email protected] 2026-03-30 2026-04-17
EMAIL [email protected] 2026-03-30 2026-04-17
URL http://sfrclak.com:8000/6202033 2026-03-30 2026-04-17
IPv4 142.11.206.73 2026-03-30 2026-04-17
HASH d6f3f62fd3b9f5432f5782b62d8cfd5… 2026-03-30 2026-04-04
HASH 07d889e2dadce6f3910dcbc253317d2… 2026-03-30 2026-04-04
HASH 2553649f2322049666871cea80a5d0d… 2026-03-30 2026-04-04
HASH df0e06df00e993e7917436d0f73df626 2026-03-31 2026-03-31
HASH 96575799bd87ae64cddbc55634a6d32d 2026-03-31 2026-03-31

Related Reports

« Back