On March 30-31, 2026, threat actors locked the core maintainer out of their accounts and compromised the axios NPM package, a widely used HTTP client downloaded over 40 million times a week.
The attackers used the access to inject a multi-platform Remote Access Trojan (RAT) into development pipelines and production environments. This post covers the attack vector, the payload, and the Tactics, Techniques, and Procedures (TTPs) deployed in the wild.
The Attack Vector: A Two-Front Compromise
The attackers pulled off a dual-account takeover of Jason Saayman, who maintains Axios on both NPM and GitHub. Working around GitHub Actions' standard OIDC provenance signing, they published malicious versions of Axios, v1.14.1 and v0.30.4, using the stolen credentials over the NPM CLI.
These releases added a new dependency called plain-crypto-js. The name was chosen to blend in with legitimate cryptographic libraries, a combosquatting trick, and the package carried the payload. Once a developer or CI/CD pipeline installed the compromised Axios package, npm's postinstall hook ran a heavily obfuscated script (node setup.js) automatically.
The Payload: Multi-Platform Sophistication
The initial dropper script used multiple layers of obfuscation: Base64 encoding, string reversal, and double XOR encryption, all to hide its intent. Once deobfuscated in memory, it checked the victim's operating system and downloaded a platform-specific Stage 2 RAT from a Command and Control (C2) server (sfrclak.com over HTTP port 8000).
- Windows: The malware deployed an 11 KB PowerShell RAT capable of reflective DLL injection, establishing persistence via a Registry Run key deceitfully named
MicrosoftUpdate. - macOS: The attackers dropped a Mach-O universal binary (supporting both Intel and Apple Silicon architectures) into
/Library/Caches/com.apple.act.mond, masquerading as a native Apple daemon process. - Linux: The script executed a Python RAT that conducted extensive system reconnaissance, tracked parent processes, and prepared the host for remote code execution.
On every affected platform, the RAT immediately enumerated the file system, focusing on sensitive directories such as .ssh, .aws, and local documents. That points to espionage or credential theft more than to a financially driven campaign.
Tactics, Techniques, and Procedures (TTPs)
To help security teams model and hunt for this threat, we have mapped the attacker's behaviors to the MITRE ATT&CK framework:
| Tactic | Technique | MITRE ID | Description of Observed Behavior |
|---|---|---|---|
| Initial Access | Supply Chain Compromise | T1195.002 | Attackers took over the maintainer's NPM and GitHub accounts to publish malicious Axios versions containing the rogue plain-crypto-js dependency. |
| Execution | Command and Scripting Interpreter | T1059 | Leveraged the npm postinstall hook (node setup.js), alongside PowerShell, Python, and AppleScript to execute the multi-stage payloads. |
| Persistence | Boot or Logon Autostart Execution | T1547.001 | Added a persistence mechanism via HKCU:\Software\Microsoft\Windows\CurrentVersion\Run\MicrosoftUpdate on Windows victims. |
| Defense Evasion | Obfuscated Files or Information | T1027 | Utilized Base64 encoding, string reversal, and position-dependent XOR encryption to hide the initial setup script. |
| Defense Evasion | Indicator Removal on Host | T1070.004 | The initial setup.js script deleted itself (fs.unlink) and altered package.json to evade post-mortem forensic analysis. |
| Defense Evasion | Reflective Code Loading | T1620 | Utilized reflective DLL injection for the Windows payload to run the .NET RAT entirely in memory. |
| Discovery | System Information / Process / File Discovery | T1082 / T1057 / T1083 | The RAT actively gathered hardware fingerprints, running processes (to spot EDRs), and enumerated target directories (e.g., .ssh). |
| Command and Control | Application Layer Protocol / Non-Standard Port | T1071.001 / T1571 | Beaconed over unencrypted HTTP on port 8000 (sfrclak.com:8000) using an antiquated IE8 User-Agent string to bypass modern inspection and SSL pinning. |
Remediation and Looking Ahead
The active window of compromise lasted roughly 3 hours and 19 minutes before NPM administrators revoked the tokens and pulled the packages. Given how widely Axios is installed, the blast radius is still vast.
Organizations must assume compromise if Axios v1.14.1 or v0.30.4 was built or deployed anywhere. Remediation means isolating affected systems, hunting for the documented IOCs, rotating all credentials, and vetting transitive dependencies.
The event is a stark reminder that the open-source trust model can fail. Strict lock files (npm ci), Software Composition Analysis (SCA), and disabling automatic npm lifecycle scripts (ignore-scripts=true in .npmrc) are no longer just best practices; they are now mandatory.
Source Reference: The technical details and forensic timeline in this post were sourced directly from the primary threat report published by OpenSource Malware: One of the most popular JavaScript packages on earth Axios has been compromised.
Protect your organization with the Threat Landscape Platform — structured intelligence, real-time IoCs, and darknet monitoring from just $49/month. Try it free.