Widespread Impact of the Axios Supply Chain Attack

2026-04-01 Paloalto Networks

https://unit42.paloaltonetworks.com/axios-supply-chain-attack/

Thumbnail for Widespread Impact of the Axios Supply Chain Attack

Unit 42 reports that compromised Axios npm releases v1.14.1 and v0.30.4 added a hidden dependency, plain-crypto-js, which executed a postinstall dropper and deployed cross-platform RAT payloads on macOS, Windows, and Linux. The infection chain used obfuscated Node.js, platform-specific downloads from sfrclak[.]com:8000, persistence on Windows, and periodic HTTP POST beaconing with commands for termination, script execution, binary payload execution, and directory enumeration. The malware performed reconnaissance, persistence, command execution, and anti-forensic cleanup, including removal of the postinstall artifacts and replacement of package metadata with a decoy. Unit 42 notes overlap with WAVESHAPER and prior activity reported as involving DPRK, but the excerpt does not independently attribute the Axios compromise beyond that overlap. The attack matters because Axios is widely used across JavaScript dependency chains, exposing organizations in multiple sectors and regions through normal npm installation workflows.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN sfrclak.com 2026-03-30 2026-04-20
HASH 58401c195fe0a6204b42f5f90995ece… 2026-03-31 2026-04-17
HASH 59336a964f110c25c112bcc5adca709… 2026-03-31 2026-04-17
HASH 5bb67e88846096f1f8d42a0f0350c9c… 2026-03-31 2026-04-17
HASH f7d335205b8d7b20208fb3ef93ee6dc… 2026-03-31 2026-04-17
HASH e10b1fa84f1d6481625f741b6989278… 2026-03-31 2026-04-17
DOMAIN callnrwise.com 2026-03-31 2026-04-17
HASH 617b67a8e1210e4fc87c92d1d1da45a… 2026-03-30 2026-04-17
HASH 92ff08773995ebc8d55ec4b8e1a225d… 2026-03-30 2026-04-17
HASH fcb81618bb15edfdedfb638b4c08a2a… 2026-03-30 2026-04-17
URL http://sfrclak.com:8000/6202033 2026-03-30 2026-04-17
IPv4 142.11.206.73 2026-03-30 2026-04-17
URL http://sfrclak.com:8000 2026-04-01 2026-04-03
HASH e49c2732fb9861548208a78e72996b9… 2026-03-31 2026-04-03
HASH a98e04dec3a7fe507eb30c72da808ba… 2026-04-01 2026-04-01
HASH 8449341ddc3f7fcc2547639e21e7044… 2026-04-01 2026-04-01
HASH cdc05cd30eb53315dadb081a7b942bb… 2026-04-01 2026-04-01
HASH ad8ba560ae5c4af4758bc68cc6dcf43… 2026-04-01 2026-04-01
HASH 9c64f1c7eba080b4e5ff17369ddcd00… 2026-04-01 2026-04-01
HASH 0d83030ab8bfba675fc1661f0756b67… 2026-04-01 2026-04-01
HASH 20df0909a3a0ef26d74ae139763a380… 2026-04-01 2026-04-01
HASH a224dd73b7ed33e0bf6a2ea340c8f88… 2026-04-01 2026-04-01
HASH 5e2ab672c3f98f21925bd26d9a9bba0… 2026-04-01 2026-04-01
HASH 7b47ed28e84437aee64ffe9770d315c… 2026-04-01 2026-04-01
HASH 526ab39d1f56732e4e926715aaa797f… 2026-04-01 2026-04-01
HASH 01c9484abc948daa525516464785009… 2026-04-01 2026-04-01
HASH 4465bdeaddc8c049a67a3d5ec105b2f… 2026-03-31 2026-04-01
HASH 506690fcbd10fbe6f2b85b49a1fffa9… 2026-03-31 2026-04-01
HASH 5b5fbc627502c5797d97b206b6dcf53… 2026-03-31 2026-04-01

Related Reports

« Back