Axios Just Got Weaponized — And Your npm install Pulled the Trigger

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A detailed technical breakdown of a supply chain attack targeting the axios npm package. An attacker compromised a maintainer account and published malicious versions (axios@1.14.1 and @0.30.4) that added a rogue dependency, plain-crypto-js, containing a postinstall script. This script silently deployed a cross-platform RAT on Windows, Linux, and macOS within seconds of running npm install. The attack exploited npm's lifecycle scripts — a by-design feature — requiring no vulnerability. Full IOCs, deobfuscated payload analysis, multi-stage execution chains per OS, and C2 communication patterns are documented.

9m read timeFrom infosecwriteups.com
Post cover image
Table of contents
The Change That Looked Completely HarmlessThis Started With Access, Not CodeThe Dependency Was Planted Ahead of Timenpm install Is Already an Execution EngineThe Loader Is Designed to Slow You DownOnce Decoded, the Behavior Is StraightforwardExecution Across PlatformsGet Itz.sanskarr’s stories in your inboxCommand and Control Begins ImmediatelyFull Remote Control CapabilityThe Timeline That Makes This DangerousAnd Then It Removes the EvidenceIndicators of CompromiseSo What Actually Happened

Sort: