The Poisoned Pipeline: Axios Supply Chain Attack

2026-03-31 Invictus IR

https://www.invictus-ir.com/news/the-poisoned-pipeline-axios-supply-chain-attack

Thumbnail for The Poisoned Pipeline: Axios Supply Chain Attack

Invictus assessed the Axios npm compromise as a separate supply-chain incident in which a lead maintainer account was hijacked to publish trojanized versions 1.14.1 and 0.30.4. The malicious releases added plain-crypto-js, deploying a cross-platform RAT against developer workstations and build environments on Windows, macOS, and Linux. Open-source researchers noted overlaps with WAVESHAPER, attributed to DPRK-nexus UNC1069, and Invictus later identified an ETag and Hostwinds infrastructure overlap tying the Axios C2 to JustJoin landing-page infrastructure associated with DPRK-nexus activity. The RAT beaconed every 60 seconds over HTTP POST with base64-encoded JSON, enumerated user/configuration paths and system telemetry, and on Windows used reflective .NET loading plus a MicrosoftUpdate run key pointing to system.bat. Key infrastructure and artifacts included sfrclak[.]com, callnrwise[.]com, 23.254.167[.]216, %PROGRAMDATA%\wt.exe, /Library/Caches/com.apple.act.mond, and /tmp/ld.py.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN sfrclak.com 2026-03-30 2026-04-20
DOMAIN callnrwise.com 2026-03-31 2026-04-17
EMAIL [email protected] 2026-03-30 2026-04-17
EMAIL [email protected] 2026-03-30 2026-04-17
IPv4 23.254.167.216 2025-01-14 2026-04-17

Related Reports

« Back