Axios npm Supply Chain Compromise (2026-03-31) — Full RE + Dynamic Analysis + BlueNoroff Attribution
Contents
You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Axios npm Supply Chain Compromise — Full Analysis Package
Date: 2026-03-31 | Attribution: BlueNoroff / Lazarus Group (HIGH confidence)
Attack: Maintainer account hijacked, cross-platform RAT deployed via [email protected] and [email protected]
What happened
On March 30-31, 2026, the npm package axios (~83M weekly downloads) was compromised through a maintainer account hijack. Two malicious versions injected [email protected], an obfuscated dropper that deploys platform-specific RATs (Windows PowerShell, macOS Mach-O C++, Linux Python). The macOS RAT is classified as NukeSped (Lazarus-exclusive). The internal project name macWebT links directly to BlueNoroff's documented RustBucket webT module from 2023.
Complete reverse engineering of all 5 payloads (full source recovered). radare2 disassembly of macOS Mach-O. setup.js deobfuscation. Memory dump analysis. Live dynamic analysis on Daytona Windows …
Axios npm Supply Chain Compromise — Full Analysis Package
Date: 2026-03-31 | Attribution: BlueNoroff / Lazarus Group (HIGH confidence)
Attack: Maintainer account hijacked, cross-platform RAT deployed via [email protected] and [email protected]
What happened
On March 30-31, 2026, the npm package axios (~83M weekly downloads) was compromised through a maintainer account hijack. Two malicious versions injected [email protected], an obfuscated dropper that deploys platform-specific RATs (Windows PowerShell, macOS Mach-O C++, Linux Python). The macOS RAT is classified as NukeSped (Lazarus-exclusive). The internal project name macWebT links directly to BlueNoroff's documented RustBucket webT module from 2023.
Complete reverse engineering of all 5 payloads (full source recovered). radare2 disassembly of macOS Mach-O. setup.js deobfuscation. Memory dump analysis. Live dynamic analysis on Daytona Windows …
IoC
http://sfrclak.com:8000
http://sfrclak.com:8000/6202033
45.61.128.54
142.11.209.109
23.254.226.130
142.11.192.0
142.11.239.46
144.172.89.231
23.254.167.216
142.11.206.73
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
656b9a2f4de6ed4909e157482860ab3d
773906b0efdefa24a7f2b8eb6985bf37
1d9437ff1aa1e958ed34a0fb0313f206
http://sfrclak.com:8000/6202033
45.61.128.54
142.11.209.109
23.254.226.130
142.11.192.0
142.11.239.46
144.172.89.231
23.254.167.216
142.11.206.73
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
656b9a2f4de6ed4909e157482860ab3d
773906b0efdefa24a7f2b8eb6985bf37
1d9437ff1aa1e958ed34a0fb0313f206