Threat Intelligence

Dissecting the Axios NPM Supply Chain Attack: A Watershed Moment in Open Source Security

TLT
Threat Landscape Team
2026-03-317 min read

On March 30-31, 2026, threat actors locked the core maintainer out of their accounts and compromised the axios NPM package, a widely used HTTP client downloaded over 40 million times a week.

The attackers used the access to inject a multi-platform Remote Access Trojan (RAT) into development pipelines and production environments. This post covers the attack vector, the payload, and the Tactics, Techniques, and Procedures (TTPs) deployed in the wild.

The Attack Vector: A Two-Front Compromise

The attackers pulled off a dual-account takeover of Jason Saayman, who maintains Axios on both NPM and GitHub. Working around GitHub Actions' standard OIDC provenance signing, they published malicious versions of Axios, v1.14.1 and v0.30.4, using the stolen credentials over the NPM CLI.

These releases added a new dependency called plain-crypto-js. The name was chosen to blend in with legitimate cryptographic libraries, a combosquatting trick, and the package carried the payload. Once a developer or CI/CD pipeline installed the compromised Axios package, npm's postinstall hook ran a heavily obfuscated script (node setup.js) automatically.

The Payload: Multi-Platform Sophistication

The initial dropper script used multiple layers of obfuscation: Base64 encoding, string reversal, and double XOR encryption, all to hide its intent. Once deobfuscated in memory, it checked the victim's operating system and downloaded a platform-specific Stage 2 RAT from a Command and Control (C2) server (sfrclak.com over HTTP port 8000).

  • Windows: The malware deployed an 11 KB PowerShell RAT capable of reflective DLL injection, establishing persistence via a Registry Run key deceitfully named MicrosoftUpdate.
  • macOS: The attackers dropped a Mach-O universal binary (supporting both Intel and Apple Silicon architectures) into /Library/Caches/com.apple.act.mond, masquerading as a native Apple daemon process.
  • Linux: The script executed a Python RAT that conducted extensive system reconnaissance, tracked parent processes, and prepared the host for remote code execution.

On every affected platform, the RAT immediately enumerated the file system, focusing on sensitive directories such as .ssh, .aws, and local documents. That points to espionage or credential theft more than to a financially driven campaign.

Tactics, Techniques, and Procedures (TTPs)

To help security teams model and hunt for this threat, we have mapped the attacker's behaviors to the MITRE ATT&CK framework:

TacticTechniqueMITRE IDDescription of Observed Behavior
Initial AccessSupply Chain CompromiseT1195.002Attackers took over the maintainer's NPM and GitHub accounts to publish malicious Axios versions containing the rogue plain-crypto-js dependency.
ExecutionCommand and Scripting InterpreterT1059Leveraged the npm postinstall hook (node setup.js), alongside PowerShell, Python, and AppleScript to execute the multi-stage payloads.
PersistenceBoot or Logon Autostart ExecutionT1547.001Added a persistence mechanism via HKCU:\Software\Microsoft\Windows\CurrentVersion\Run\MicrosoftUpdate on Windows victims.
Defense EvasionObfuscated Files or InformationT1027Utilized Base64 encoding, string reversal, and position-dependent XOR encryption to hide the initial setup script.
Defense EvasionIndicator Removal on HostT1070.004The initial setup.js script deleted itself (fs.unlink) and altered package.json to evade post-mortem forensic analysis.
Defense EvasionReflective Code LoadingT1620Utilized reflective DLL injection for the Windows payload to run the .NET RAT entirely in memory.
DiscoverySystem Information / Process / File DiscoveryT1082 / T1057 / T1083The RAT actively gathered hardware fingerprints, running processes (to spot EDRs), and enumerated target directories (e.g., .ssh).
Command and ControlApplication Layer Protocol / Non-Standard PortT1071.001 / T1571Beaconed over unencrypted HTTP on port 8000 (sfrclak.com:8000) using an antiquated IE8 User-Agent string to bypass modern inspection and SSL pinning.

Remediation and Looking Ahead

The active window of compromise lasted roughly 3 hours and 19 minutes before NPM administrators revoked the tokens and pulled the packages. Given how widely Axios is installed, the blast radius is still vast.

Organizations must assume compromise if Axios v1.14.1 or v0.30.4 was built or deployed anywhere. Remediation means isolating affected systems, hunting for the documented IOCs, rotating all credentials, and vetting transitive dependencies.

The event is a stark reminder that the open-source trust model can fail. Strict lock files (npm ci), Software Composition Analysis (SCA), and disabling automatic npm lifecycle scripts (ignore-scripts=true in .npmrc) are no longer just best practices; they are now mandatory.


Source Reference: The technical details and forensic timeline in this post were sourced directly from the primary threat report published by OpenSource Malware: One of the most popular JavaScript packages on earth Axios has been compromised.


Protect your organization with the Threat Landscape Platform — structured intelligence, real-time IoCs, and darknet monitoring from just $49/month. Try it free.

Ready to Transform Your Threat Intelligence?

See how Threat Landscape can reduce alert fatigue and improve your security operations