PULSE NAME
NPM Package Supply Chain Compromise Leads to RAT Deployment
WHITE AlienVault 2026-04-10 Modified: 2026-04-10
7
IOCs
LOW VOLUME
A supply chain attack targeting the Axios npm package has been identified after threat actors compromised the npm account of the company's lead developer. Malicious versions (axios@1.14.1 and axios@0.30.4) were published containing a hidden dependency that executed postinstall scripts during npm installation. This automated execution downloaded and deployed a remote access trojan on affected systems without requiring user interaction, making it particularly dangerous for developer environments and CI/CD pipelines. The compromise resulted in full remote access capabilities, potential credential exposure including API keys and SSH keys, and possible insertion of malicious code into software builds. Detection platforms identified suspicious process execution chains involving npm spawning command interpreters and network utilities, followed by outbound connections to attacker-controlled infrastructure.
Indicators of Compromise (7)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 04e3073b3cd5c5bfcde6f575ecf6e8c1 2026-04-10
FileHash-MD5 7658962ae060a222c0058cd4e979bfa1 2026-04-10
FileHash-SHA1 a90c26e7cbb3440ac1cad75cf351cbedef7744a8 2026-04-10
FileHash-SHA1 b0e0f12f1be57dc67fa375e860cedd19553c464d 2026-04-10
FileHash-SHA256 617b67a8e1210e4fc87c92d1d1da45a2f311c08d26e89b12307cf583c900d101 2026-04-10
FileHash-SHA256 e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09 2026-04-10
domain sfrclak.com 2026-04-10