PULSE NAME
Threat Brief: Widespread Impact of the Axios Supply Chain Attack
WHITE AlienVault 2026-04-01 Modified: 2026-04-08
45
IOCs
MEDIUM VOLUME
A sophisticated supply chain attack compromised the Axios JavaScript library after threat actors hijacked an npm maintainer account, releasing malicious versions v1.14.1 and v0.30.4. These versions contained a hidden dependency called plain-crypto-js, which deployed a cross-platform remote access Trojan affecting Windows, macOS, and Linux systems. The malware performed reconnaissance, established persistence, and included self-destruct capabilities for evasion. Using a heavily obfuscated dropper script, the attack fetched platform-specific payloads from a command-and-control server while disguising traffic as legitimate npm registry requests. All variants shared identical C2 protocols and beaconed every 60 seconds. The campaign impacted multiple sectors across the U.S., Europe, Middle East, South Asia, and Australia, with analysis showing overlap with DPRK-linked operations.
Indicators of Compromise (8 / 45 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 07d889e2dadce6f3910dcbc253317d28ca61c766 2026-04-01
FileHash-SHA1 13ab317c5dcab9af2d1bdb22118b9f09f8a4038e 2026-04-01
FileHash-SHA1 2553649f2322049666871cea80a5d0d6adc700ca 2026-04-01
FileHash-SHA1 59faac136680104948e083b3b67a70af9bfa5d5e 2026-04-01
FileHash-SHA1 978407431d75885228e0776913543992a9eb7cc4 2026-04-01
FileHash-SHA1 a90c26e7cbb3440ac1cad75cf351cbedef7744a8 2026-04-01
FileHash-SHA1 ae39c4c550ad656622736134035f17ca7a66a742 2026-04-01
FileHash-SHA1 b0e0f12f1be57dc67fa375e860cedd19553c464d 2026-04-01