PULSE NAME
Detections for the Axios supply chain compromise
WHITE AlienVault 2026-04-07 Modified: 2026-04-07
24
IOCs
MEDIUM VOLUME
A supply chain attack targeting Axios npm package versions 1.14.1 and 0.30.4 introduced a malicious transitive dependency (plain-crypto-js@4.2.1) that executed during installation. The attack deploys cross-platform payloads across Linux, Windows, and macOS through a consistent pattern: Node.js spawns OS-native shells to retrieve and execute remote payloads in detached or hidden contexts. Linux victims receive a Python-based RAT, Windows systems get a PowerShell backdoor with registry persistence, and macOS hosts are compromised with a Mach-O binary backdoor. All variants beacon to the same C2 infrastructure, performing host fingerprinting, process enumeration, filesystem reconnaissance, and arbitrary code execution. The malicious activity is reliably detected through behavioral signatures focusing on unusual Node.js process ancestry and remote payload retrieval rather than static indicators.
Indicators of Compromise (6 / 24 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 7658962ae060a222c0058cd4e979bfa1 2026-04-07
FileHash-MD5 7a9ddef00f69477b96252ca234fcbeeb 2026-04-07
FileHash-MD5 8c782b59a786f18520673e8d669e3b0a 2026-04-07
FileHash-MD5 90e8e227ba8bef0ea7e0212b5b1e0d4c 2026-04-07
FileHash-MD5 db7f4c82c732e8b107492cae419740ab 2026-04-07
FileHash-MD5 e56bafda15a624b60ac967111d227bf8 2026-04-07