PULSE NAME
Threat Brief: Widespread Impact of the Axios Supply Chain Attack
WHITE AlienVault 2026-04-01 Modified: 2026-04-08
45
IOCs
MEDIUM VOLUME
A sophisticated supply chain attack compromised the Axios JavaScript library after threat actors hijacked an npm maintainer account, releasing malicious versions v1.14.1 and v0.30.4. These versions contained a hidden dependency called plain-crypto-js, which deployed a cross-platform remote access Trojan affecting Windows, macOS, and Linux systems. The malware performed reconnaissance, established persistence, and included self-destruct capabilities for evasion. Using a heavily obfuscated dropper script, the attack fetched platform-specific payloads from a command-and-control server while disguising traffic as legitimate npm registry requests. All variants shared identical C2 protocols and beaconed every 60 seconds. The campaign impacted multiple sectors across the U.S., Europe, Middle East, South Asia, and Australia, with analysis showing overlap with DPRK-linked operations.
Indicators of Compromise (8 / 45 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 04e3073b3cd5c5bfcde6f575ecf6e8c1 2026-04-01
FileHash-MD5 089e2872016f75a5223b5e02c184dfec 2026-04-01
FileHash-MD5 21d2470cae072cf2d027d473d168158c 2026-04-01
FileHash-MD5 7658962ae060a222c0058cd4e979bfa1 2026-04-01
FileHash-MD5 7a9ddef00f69477b96252ca234fcbeeb 2026-04-01
FileHash-MD5 8c782b59a786f18520673e8d669e3b0a 2026-04-01
FileHash-MD5 9663665850cdd8fe12e30a671e5c4e6f 2026-04-01
FileHash-MD5 db7f4c82c732e8b107492cae419740ab 2026-04-01