← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
NPM Package Supply Chain Compromise Leads to RAT Deployment
A supply chain attack targeting the Axios npm package has been identified after threat actors compromised the npm account of the company's lead developer. Malicious versions (axios@1.14.1 and axios@0.30.4) were published containing a hidden dependency that executed postinstall scripts during npm installation. This automated execution downloaded and deployed a remote access trojan on affected systems without requiring user interaction, making it particularly dangerous for developer environments and CI/CD pipelines. The compromise resulted in full remote access capabilities, potential credential exposure including API keys and SSH keys, and possible insertion of malicious code into software builds. Detection platforms identified suspicious process execution chains involving npm spawning command interpreters and network utilities, followed by outbound connections to attacker-controlled infrastructure.
MITRE ATT&CK & Malware Families
Indicators of Compromise (7)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 04e3073b3cd5c5bfcde6f575ecf6e8c1 | — | 2026-04-10 | |
| FileHash-MD5 | 7658962ae060a222c0058cd4e979bfa1 | — | 2026-04-10 | |
| FileHash-SHA1 | a90c26e7cbb3440ac1cad75cf351cbedef7744a8 | — | 2026-04-10 | |
| FileHash-SHA1 | b0e0f12f1be57dc67fa375e860cedd19553c464d | — | 2026-04-10 | |
| FileHash-SHA256 | 617b67a8e1210e4fc87c92d1d1da45a2f311c08d26e89b12307cf583c900d101 | — | 2026-04-10 | |
| FileHash-SHA256 | e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09 | — | 2026-04-10 | |
| domain | sfrclak.com | — | 2026-04-10 |