PULSE NAME
Securing the Supply Chain: How SentinelOne's AI EDR Stops the ...
WHITE AlienVault 2026-04-03 Modified: 2026-04-03
12
IOCs
MEDIUM VOLUME
On March 31, 2026, a North Korean state actor hijacked the npm credentials of the primary Axios maintainer and published two backdoored releases that deployed a cross-platform remote access trojan (RAT) to Windows, macOS, and Linux systems. Axios is the most widely used HTTP client in the JavaScript ecosystem, with approximately 100 million weekly downloads and a presence in roughly 80% of cloud and code environments.
Indicators of Compromise (3 / 12 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 07d889e2dadce6f3910dcbc253317d28ca61c766 2026-04-03
FileHash-SHA1 2553649f2322049666871cea80a5d0d6adc700ca 2026-04-03
FileHash-SHA1 d6f3f62fd3b9f5432f5782b62d8cfd5247d5ee71 2026-04-03