UPDATE--A significant supply chain attack has hit the immensely popular axios npm package, leading to the installation of a small RAT on victim machines. For a brief, critical window of a few hours on Tuesday morning, a threat actor compromised a maintainer's npm account and published two malicious versions of the package (v1.14.1 and v0.30.4).

Given that axios is a dependency in nearly 80% of all cloud and code environments and sees approximately 100 million downloads per week, this intrusion represents a serious concern for the community despite the limited window of exposure for the compromised packages. Even with a quick takedown, the short exposure window was enough to result in observed execution of the trojanized package in 3% of affected environments, according to researchers at Wiz.

Google's Threat Intelligence Group has attributed this attack to a North Korean actor it calls UNC1069 that has a history of intrusions focused on cryptocurrency heists. The attirbution is based in part on the deployment of a backdoor called Waveshaper.v2, which is a direct descendant of a piece of malware this group has used in the past.

"Analysis of the C2 infrastructure (sfrclak[.]com resolving to 142.11.206.73) revealed connections from a specific AstrillVPN node previously used by UNC1069. Additionally, adjacent infrastructure hosted on the same ASN has been historically linked to UNC1069 operations," the Google analysis says.

The attacker was able to compromise the GitHub and npm accounts of one of the maintainers of axios in the early morning hours Tuesday and then added a trojanized package called plain-crypto-js as a dependency to the two compromised versions. 

The axios maintainers have removed the compromised packages. Axios is ubiquitous and is deployed so widely that it is essentially a load-bearing part of the web ecosystem.

“When the attack first happened, Axios maintainers were unable to regain control of the project. In a public GitHub issue, a collaborator stated they could not revoke access from the account responsible for the malicious publish, noting that the attacker’s permissions exceed their own,” researchers at Socket said in a comprehensive analysis of the incident. 

The Socket team said there is no indication right now that the axios intrusion is related to the recent TeamPCP supply chain attacks. 

“The malicious package includes a dropper (setup.js) that downloads and executes platform-specific second-stage payloads from sfrclak.com:8000, and then self-cleans by deleting itself and restoring a clean package.json. The second-stage payloads function as lightweight remote access trojans (RATs) and beacon to the C2 server every 60 seconds, transmitting system inventory and awaiting commands,” the Wiz analysis says. 

“All three variants implement similar capabilities, including remote shell execution, binary injection, directory browsing, process listing, and system reconnaissance, while differing by operating system.”

Infection Chain:

  1. Compromise and Publication: The attack began with the compromise of an axios maintainer's npm account, allowing the actor to publish the tainted v1.14.1 and v0.30.4 versions directly to the registry.
  2. The Dropper (setup.js): The malicious plain-crypto-js package contained a dropper script (setup.js).
  3. Second-Stage Payload: The dropper’s primary function was to download and execute platform-specific second-stage payloads from a C2 server at sfrclak.com:8000.
  4. Self-Cleaning: Crucially, the dropper attempted to erase its tracks by deleting itself and restoring a clean package.json file.

Payload Capabilities

The ultimate payloads, which functioned as lightweight RATs, were designed for full system reconnaissance and control.The RAT gave the attacker several capabilities on target systems, including remote shell execution, binary injection, data exfiltration, and system reconnaissance. After execution, the malware deletes itself and takes other actions to eliminate traces on compromised machines.

Platform Specifics

OSPayload DetailsPersistence/Evasion
macOSC++ compiled Mach-O universal binary.Capable of self-signing injected payloads via codesign.
WindowsPowerShell script.Achieved persistence via a registry Run key (MicrosoftUpdate) and a re-download batch file.
LinuxDelivered as a Python script.Focused on system inventory and remote control.

Immediate Action Required

Due to the high-stakes nature of this attack, all organizations and individual developers must assume potential exposure and perform an immediate security audit when possible.

1. Audit Dependencies Now

The highest priority is to search your codebase and deployment environments for the following malicious versions:

  • axios@1.14.1
  • axios@0.30.4

If either of these versions is found in any of the package-lock.json, yarn.lock, or running applications, treat the affected environment as compromised.

2. Isolate and Scan

If a malicious version was executed in your environment:

  • Isolate: Immediately quarantine the affected system or container.
  • Indicators of Compromise (IoCs): Look for network traffic beaconing to the Command and Control (C2) server: sfrclak.com:8000.
  • Windows Persistence: Check the registry for the persistence key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\MicrosoftUpdate.

3. Reference the Official Advisories

Track this vulnerability using the official advisories for a complete list of IoCs and real-time updates:

For ongoing updates about the intrusion and the downstream effects, keep an eye on the Socket blog and Huntress blog. 

This story was updated on April 1 to add attribution information from Google.