Supply Chain Compromise of axios npm Package
2026-03-31 • Huntress •
https://www.huntress.com/blog/supply-chain-compromise-axios-npm-package
Huntress observed active exploitation of the axios npm supply-chain compromise, with malicious [email protected] and [email protected] delivering a cross-platform RAT through the [email protected] postinstall hook. The update notes multiple indicators pointing to North Korean state-sponsored activity, including overlaps between the macOS payload and a DPRK-linked backdoor, the macWebT project name’s connection to BlueNoroff’s RustBucket webT module, and Google Threat Intelligence Group attribution to UNC1069. Huntress reported at least 135 monitored endpoints contacting attacker C2 during the exposure window and documented Windows tradecraft including VBScript staging, a copied powershell.exe masquerading as %PROGRAMDATA%\wt.exe, and persistence via system.bat plus an HKCU Run key. The report advises treating affected hosts as fully compromised because the RAT supported credential theft, data exfiltration, reconnaissance, and follow-on execution even after the npm packages and C2 infrastructure were removed.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | sfrclak.com | 2026-03-30 | 2026-04-20 |
| HASH | f7d335205b8d7b20208fb3ef93ee6dc… | 2026-03-31 | 2026-04-17 |
| DOMAIN | calltan.com | 2026-03-31 | 2026-04-17 |
| DOMAIN | callnrwise.com | 2026-03-31 | 2026-04-17 |
| HASH | 617b67a8e1210e4fc87c92d1d1da45a… | 2026-03-30 | 2026-04-17 |
| HASH | 92ff08773995ebc8d55ec4b8e1a225d… | 2026-03-30 | 2026-04-17 |
| HASH | fcb81618bb15edfdedfb638b4c08a2a… | 2026-03-30 | 2026-04-17 |
| [email protected] | 2026-03-30 | 2026-04-17 | |
| [email protected] | 2026-03-30 | 2026-04-17 | |
| URL | http://sfrclak.com:8000/6202033 | 2026-03-30 | 2026-04-17 |
| IPv4 | 142.11.206.73 | 2026-03-30 | 2026-04-17 |
| HASH | d6f3f62fd3b9f5432f5782b62d8cfd5… | 2026-03-30 | 2026-04-04 |
| HASH | 07d889e2dadce6f3910dcbc253317d2… | 2026-03-30 | 2026-04-04 |
| HASH | 2553649f2322049666871cea80a5d0d… | 2026-03-30 | 2026-04-04 |
| HASH | df0e06df00e993e7917436d0f73df626 | 2026-03-31 | 2026-03-31 |
| HASH | 96575799bd87ae64cddbc55634a6d32d | 2026-03-31 | 2026-03-31 |