Unit 42 researchers detail a supply chain attack targeting the Axios JavaScript library after an npm maintainer account was hijacked. Malicious versions v1.14.1 and v0.30.4 injected a hidden dependency called plain-crypto-js, which acted as a cross-platform RAT affecting Windows, macOS, and Linux. The dropper used obfuscation
Table of contents
Executive SummaryDetails of the Axios Supply Chain AttackUnit 42 Managed Threat Hunting QueriesConclusionPalo Alto Networks Product Protections for the Axios Supply Chain AttackIndicators of CompromiseSort: