HomeSecurityAxios Supply Chain Attack: Malicious versions distribute RAT

Axios Supply Chain Attack: Malicious versions distribute RAT

The popular HTTP client Axios has been hit by a supply chain attack when two new versions of the npm package introduced a malicious dependency. Versions 1.14.1 and 0.30.4 of Axios introduced the “ plain-crypto-js ” package version 4.2.1 as a fake dependency, putting millions of developers worldwide at risk. This attack represents one of the most sophisticated attacks on the JavaScript ecosystem in recent years.

Axios

According to StepSecurity , the two releases were published using the compromised npm credentials of the Axios main maintainer , allowing the attackers to bypass the project's GitHub Actions CI/CD pipeline

Security researcher Ashish Kurmi explained that the sole purpose of the malicious package is to execute a postinstall script that acts as a cross-platform remote access trojan (RAT) dropper, targeting macOS, Windows , and Linux. The dropper communicates with an active command and control server and delivers second-stage payloads for each platform. After execution, the malware deletes itself and replaces its own package.json with a clean version to avoid detection. This self-destruction technique makes forensic analysis extremely difficult and allows the malware to remain hidden for long periods of time.

Axios Attack Timeline and Technical Details

With over 83 million weekly downloads, Axios is one of the most widely used HTTP clients in the JavaScript ecosystem across frontend frameworks, backend services, and enterprise applications. The attack was not opportunistic – the malicious dependency existed for 18 hours , with three separate payloads pre-built for three operating systems. This level of preparation indicates a highly organized and experienced threat actor with a deep understanding of the intricacies of the npm ecosystem .

See also: Open VSX: Supply Chain attack distributes GlassWorm via compromised dev account

The timing of the attack reveals its premeditated nature:

On March 30, 2026, a clean version of the “plain-crypto-js@4.2.0” package was published. At 23:59 UTC on the same day, a new version with the payload was published. On March 31, within 39 minutes, both malicious versions of Axios using the compromised account. This speed suggests automated tools and pre-written scripts to execute the attack.

According to StepSecurity , the threat actor behind the campaign compromised the npm administrator account and changed his email address to a Proton Mail address under his control. “ plain-crypto-js ” was published by an npm user named “ nrwise ” with the email address “ nrwise@proton.me ”.

It is believed that the attacker obtained a long-lived classic npm access token for the account. This tactic allows attackers to maintain access even if the legitimate account owner changes their password.

Axios Supply Chain Attack: Malicious versions distribute RAT

Attack Techniques for Multiple Platforms

The embedded malware is launched via an obfuscated Node.js dropper (“setup.js”) and is designed to adapt based on the operating system. On macOS, it executes an AppleScript payload to fetch a trojan binary from an external server, stores it as “/Library/Caches/com.apple.act.mond” and executes it in the background via /bin/zsh. On Windows, it locates the PowerShell binary path, copies it to “%PROGRAMDATA%\wt.exe” (disguised as a Windows Terminal application) and executes a VBScript that communicates with the same server to fetch a PowerShell RAT script.

See also: New malicious packages revealed in NuGet Supply Chain Attack

On other platforms such as Linux , the dropper executes a shell command via Node.js execSync to fetch a Python RAT script from the same server, saves it to “/tmp/ld.py” and runs it in the background using the nohup command .

Each platform sends a distinct POST body to the same C2 URL – packages.npm.org/product0 (macOS), packages.npm.org/product1 (Windows), packages.npm.org/product2 (Linux). This architecture allows the C2 server to serve the appropriate payload depending on the platform through a single endpoint.

The downloaded second-stage binary for macOS is a C++ RAT that fingerprints the system and beacons to a remote server to retrieve commands for subsequent execution. It supports capabilities to execute additional payloads, execute shell commands, enumerate the file system , and terminate the RAT.

SafeDep's analysis of the Linux RAT revealed that it supports the same commands as its macOS counterpart. The lack of a persistence mechanism means that the malware does not survive reboots. This suggests that the attack is either geared towards quick data extraction or leverages the RAT's ability to execute binaries and shell commands to develop persistence.

Once the main payload is launched, the Node.js malware also performs three forensic cleanup, removing the postinstall script from the installed package directory, deleting “package.json”, and renaming “package.md” to “package.json”.

It is worth noting that the “package.md” file is included in “plain-crypto-js” and is a pure “package.json” manifest without the postinstall hook that triggers the entire attack.

Axios Supply Chain Attack: Malicious versions distribute RAT

Ecosystem Defense and Protection Strategies

  • Check for malicious versions of Axios.
  • Check for RAT artifacts: “/Library/Caches/com.apple.act.mond” (macOS), “%PROGRAMDATA%\wt.exe” (Windows) and “/tmp/ld.py” (Linux).
  • Downgrade to Axios versions 1.14.0 or 0.30.3.
  • Remove “plain-crypto-js” from the “node_modules” directory.
  • If RAT artifacts are detected, assume they have been compromised and change all credentials on the system.
  • Check your CI/CD pipelines for runs that installed the affected versions.
  • Block egress traffic to the command-and-control domain (“sfrclak[.]com”)

See also: Supply chain attacks: Why attacks via third-party partners are increasing

This attack highlights the criticality of supply chain security in the modern software development ecosystem and the need for defense-in-depth approaches. Using hardware keys for 2FA instead of TOTP can prevent phishing attacks, while conducting regular supply chain audits and implementing cooldown periods for new packages are key security practices. As reported by The Hacker News, this particular campaign was designed to evade detection and analysis, highlighting the need for proactive protection measures.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS