Six npm packages delivered an identical JavaScript loader, including three hijacked legitimate packages and three packages published with the malware already embedded. The loader used an Ethereum transaction as a dead drop, decoding command-and-control IP…
Search
Reports (91)
DPRK's PolinRider campaign automatically poisoned legitimate npm packages and Go modules after compromising developer machines, rather than deliberately selecting high-value packages for account takeover. OpenSourceMalware linked 20 analyzed packages thro…
Two malicious beta releases in the legitimate `@joyfill` npm scope executed an obfuscated loader when applications imported their production bundles. The loader resolved encrypted payloads through two successive Tron-to-BSC transaction chains, selected C2…
Two Joyfill beta packages contained an import-time JavaScript implant that used Tron, Aptos, and BNB Smart Chain transactions to resolve mutable payloads. The recovered chain delivered a DEV#POPPER Node.js RAT capable of remote command execution, file tra…
Malicious prerelease builds of `@joyfill/components` and `@joyfill/layouts` executed an obfuscated Node.js loader when imported, bypassing protections focused on npm installation scripts. The implant used blockchain transactions to resolve later stages, d…
Checkmarx identified seven malicious npm packages that impersonated Vite-related scopes and delivered an obfuscated remote-access trojan through Tron, Aptos, and Binance Smart Chain infrastructure. Shared wallets, XOR keys, loader structure, and payloads …
`nodemon-sudo` v3.1.16 is a malicious npm lookalike that copies legitimate nodemon while adding an unused dependency on `tslint-conf`, a repackaged pino logger containing the backdoor. The payload avoids install hooks and import-time execution; it runs on…
JFrog identified a Lazarus-linked npm supply-chain campaign that hid malicious code in Rollup-themed lookalike packages and SVG utility second stages. The packages fetched a JSONKeeper payload, decrypted a remote stage from 216.126.236.244, and launched N…
Sapphire Sleet compromised the `ehindero` npm maintainer account and injected the malicious `[email protected]` dependency into 144 Mastra AI npm packages during an 88-minute window on June 17, 2026. The postinstall hook executed an obfuscated JavaScrip…
The malicious npm packages `chalk-ultra` and `vitest-cli` execute a hidden downloader that steals developer credentials, source code, browser data, and cryptocurrency-wallet information. The payload can replace Chrome's MetaMask extension with a persisten…
Melted in Hex reverses PolinRider, a DPRK/Lazarus-attributed npm supply-chain loader hidden in the functional packages tailwind-color-shades and safe-validate. The loader executes on import, resolves encrypted stages through TRON, Aptos, and Binance Smart…
A hijacked npm maintainer account republished more than 140 Mastra packages with one added dependency on the typosquatted `easy-day-js` package, leaving Mastra's own library code unchanged while moving malware one dependency hop away. The malicious `easy-…
From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet
Sapphire Sleet compromised the Mastra npm ecosystem by taking over the `ehindero` maintainer account and injecting the malicious `easy-day-js` typosquat into more than 140 `mastra` and `@mastra` packages. The weaponized package ran a postinstall dropper t…
An attacker reused a dormant former Mastra contributor npm account to republish 143 @mastra packages on June 17, 2026, adding a dependency on easy-day-js that resolved to a malicious postinstall version. The dropper fetched a second-stage Node RAT from Ho…
A compromised Mastra npm release wave added the typosquatted dependency `easy-day-js`, whose `postinstall` hook executed during dependency installation and pulled a second-stage Node.js implant from attacker-controlled infrastructure. The implant installe…
A malicious npm dependency, easy-day-js, was added to 143 Mastra packages as a production dependency, causing fresh installs to resolve from a clean decoy version to weaponized [email protected] through a caret version range. Its obfuscated postinstall …
An attacker compromised the @mastra npm organization and republished more than 140 Mastra ecosystem packages with a dependency on the typosquatted `easy-day-js` package. The malicious `[email protected]` release used a postinstall dropper to disable TLS…
ESRC found that the malicious npm package chai-as-init, distributed in versions 1.4.5 through 1.4.7, impersonated a Chai.js plugin while hiding malicious code in only two files copied into a mostly legitimate-looking pino package tree. Loading the package…
A stale former contributor npm account was used to republish the Mastra npm scope with a malicious `easy-day-js` dependency that executed at install time. The dropper disabled TLS validation, fetched a second-stage payload from a raw IP, and installed a c…
Checkmarx identified ChainVeil, an npm typosquatting campaign attributed to an actor it calls SuccessKey that distributed at least nine malicious packages containing a shared import-time loader. The loader used Tron, Aptos, and Binance Smart Chain transac…
Sonatype attributes a malicious npm brandjacking campaign to Lazarus Group, involving dozens of packages that imitate or appear adjacent to trusted JavaScript ecosystems such as Buffer, Chai, and React. Analysis of `buffer-utilities` shows a dropper that …
SANS ISC analyzes an obfuscated Node.js stealer uploaded as `extracted-decoded.js`, with a heavily obfuscated execution wrapper but plain-text embedded payload modules. The malware targets Windows through WSL, macOS, and Linux, stealing Chromium-family br…
OX Security identified a malicious npm package, terminal-logger-utils, with keylogger, infostealer, and RAT behavior and linked the activity to previously documented North Korean supply-chain campaigns. The package is triggered through a postinstall hook …
OpenSourceMalware found three malicious npm packages linked to the March 2026 Axios compromise through the shared XOR key OrDeR_7077, while using separate C2 infrastructure at 18.208.244.120:9999. The packages redeem-onchain-sdk, nicegui, and period-newli…
OpenSourceMalware shows how malicious packages and repositories abuse legitimate developer automation so payloads can run during `npm install` or when a repository is opened in VS Code. The DPRK-relevant section notes Lazarus-linked Contagious Interview a…
Panther Threat Research tracked a DPRK-linked npm supply-chain campaign that published 108 malicious packages and 261 versions between March 20 and April 20, 2026. The activity is attributed with high confidence to Famous Chollima / DeceptiveDevelopment b…
Axios maintainer access was compromised to publish malicious [email protected] and [email protected] releases that added the typosquatted dependency [email protected] without changing the main Axios source. The malicious dependency used a postinstall hook to ru…
A malicious npm package named js-logger-pack evolved from harmless probes into a full multi-platform infostealer and later a HuggingFace-hosted binary dropper. Weaponized versions installed a Linux SSH backdoor, exfiltrated Telegram Desktop sessions, stol…
Panther analyzed [email protected], an npm package attributed in the excerpt to DPRK/Famous Chollima activity and built to target developers running automated Polymarket trading bots. The package masqueraded as a logging utility and executed at require()…
Malicious Axios npm versions `[email protected]` and `[email protected]` were observed in a customer environment after attackers abused npm lifecycle execution through a hidden dependency. The postinstall chain launched shell and PowerShell activity, downloaded a s…
An investigation into the Mentonex GitHub organization found an active npm backdoor chain, fake developer personas, and facilitator-recruitment activity that the author says maps closely to documented DPRK tradecraft. The malicious chain used logkitx, log…
A cluster of malicious npm packages published between April 6 and April 9, 2026 delivered OtterCookie variants, described as a credential-theft and backdoor toolchain attributed to North Korean threat actors. The campaign used a two-layer supply-chain pat…
eSentire reports that two malicious Axios npm versions, 1.14.1 and 0.30.4, were published through a compromised maintainer account and remained live for about three hours. The tampered packages added a malicious dependency that ran a postinstall payload, …
A compromise of the Axios npm package introduced malicious versions 1.14.1 and 0.30.4 that added a covert dependency and executed a postinstall payload when developers or CI/CD systems installed the package. The excerpt attributes the activity to UNC1069,…
NVISO describes hunting and response activity for the Axios npm supply-chain incident, where compromised Axios releases added the trojanized [email protected] dependency and deployed cross-platform RAT payloads. Its MDR telemetry observed activity mai…
Cisco Talos found that attackers published malicious Axios npm versions 1.14.1 and 0.30.4 on March 31, 2026, leaving the widely used JavaScript HTTP client exposed for about three hours. The modified packages introduced a fake dependency, plain-crypto-js,…
DCSO analyzed public indicators from the axios npm compromise and found infrastructure overlaps suggesting possible connections to the DPRK-linked BlueNoroff cluster. The attacker used newly created Proton Mail accounts, compromised the axios maintainer a…
Two malicious Axios versions, 1.14.1 and 0.30.4, were published to npm on March 31, 2026 after the lead maintainer's account was compromised. The attacker injected [email protected], which installed a remote access trojan on macOS, Windows, and Linux …
Two malicious Axios releases briefly published to npm introduced a dependency that installed a remote access trojan across macOS, Windows, and Linux. Axios maintainer Jason Saayman said the compromise began with a targeted social engineering operation in …
The npm package express-session-js typosquatted the legitimate express-session middleware and executed malicious code as a side effect of require(), rather than through an install hook. Its dropper retrieved an obfuscated stage-two payload from jsonkeeper…
Google Threat Intelligence Group reports that malicious axios releases 1.14.1 and 0.30.4 introduced plain-crypto-js as a dependency, triggering a postinstall dropper that deployed WAVESHAPER.V2 backdoors across Windows, macOS, and Linux. GTIG attributes t…
Microsoft attributed the malicious axios npm releases 1.14.1 and 0.30.4 and their command-and-control infrastructure to Sapphire Sleet, a North Korean state actor. The compromise inserted the fake dependency [email protected] so npm installation or up…
CrowdStrike reports that a threat actor used stolen maintainer credentials on March 31, 2026 to compromise the widely used Axios npm package and deploy updated, platform-specific ZshBucket variants. The activity is attributed to STARDUST CHOLLIMA with mod…
Malicious Axios npm releases 1.14.1 and 0.30.4 allegedly used a compromised maintainer account to add the hidden [email protected] dependency, causing npm install to execute a postinstall dropper. The excerpt attributes the operation to UNC1069, descr…
Bitdefender attributes the axios incident to an unknown threat actor, not to any named state group, and describes a supply-chain compromise of the primary maintainer's npm account. The attacker published [email protected] and [email protected] with a hidden plain-c…
StepSecurity identified malicious npm releases [email protected] and [email protected] published through compromised maintainer credentials rather than the project’s normal GitHub Actions OIDC Trusted Publisher flow. The attacker added an unused runtime dependency,…
Socket analyzed the axios supply-chain compromise in which [email protected] and [email protected] pulled the malicious [email protected] dependency through npm. The dependency’s postinstall hook ran setup.js, decoded obfuscated module names, commands, paths, a…
ThreatBook attributes the Axios npm supply-chain poisoning incident to Lazarus Group, citing long-term tracking, malware behavior, and infrastructure pivots. The attack used a hijacked Axios maintainer account to publish [email protected] and [email protected] with…
Datadog analyzes the March 31, 2026 axios npm compromise in which a hijacked maintainer account published [email protected] and [email protected] with a new dependency on plain-crypto-js. The typosquatted package cloned crypto-js but added a postinstall setup.js sc…
An attacker hijacked the npm account of Axios lead maintainer jasonsaayman and published malicious axios versions 1.14.1 and 0.30.4 on March 31, 2026. The poisoned releases added [email protected], whose postinstall script ran during npm install and d…
Malicious axios versions 1.14.1 and 0.30.4 were published to npm through a compromised maintainer account, affecting both modern and legacy branches of a package with more than 100 million weekly downloads. The attacker did not alter Axios source code dir…
Huntress observed active exploitation of the axios npm supply-chain compromise, with malicious [email protected] and [email protected] delivering a cross-platform RAT through the [email protected] postinstall hook. The update notes multiple indicators pointing …
Axios npm Supply Chain Compromise (2026-03-31) — Full RE + Dynamic Analysis + BlueNoroff Attribution
The analysis attributes the March 2026 axios npm supply-chain compromise to BlueNoroff/Lazarus with high confidence, citing NukeSped classification, macWebT naming overlap with RustBucket webT, matching User-Agent behavior, Hostwinds infrastructure, and c…
Malicious axios versions 1.14.1 and 0.30.4 were briefly published to npm after likely compromise of a maintainer account, exposing developers and CI/CD systems that installed them during the live publication window. The attacker did not alter Axios source…
SafeDep identified malicious axios releases 1.14.1 and 0.30.4 published to npm after an apparent maintainer account compromise, with no matching GitHub tag or provenance for the 1.14.1 package. The attacker made a narrow manifest-only change by adding the…
Derp's analysis found that Axios 1.14.1 introduced a single new dependency, [email protected], whose postinstall hook ran an obfuscated JavaScript dropper during npm install. The compromise lasted 169 minutes, affected Axios 1.14.1 and 0.30.4, and use…
OX Security analyzes a supply-chain compromise of axios versions 0.30.4 and 1.14.1 through the malicious [email protected] dependency. The dependency's postinstall setup.js script contacted sfrclak[.]com on port 8000, fingerprinted the operating syste…
Sophos CTU reported that Axios versions 1.14.1 and 0.30.4 were compromised after an apparent npm maintainer account takeover and used to deploy a cross-platform RAT. The malicious dependency executed during installation, retrieved platform-specific second…
Trend Micro reported that attackers hijacked the Axios npm maintainer account and manually published malicious Axios versions 1.14.1 and 0.30.4 using stolen credentials rather than the project’s normal OIDC Trusted Publisher workflow. The poisoned release…
Wiz reports that an unknown actor compromised an axios maintainer npm account on March 31, 2026 and published malicious axios versions 1.14.1 and 0.30.4. The poisoned releases introduced plain-crypto-js, whose setup.js dropper downloaded second-stage payl…
Attackers compromised the npm account of Axios maintainer jasonsaayman, likely through a long-lived classic npm token, and published malicious Axios versions 1.14.1 and 0.30.4. The only Axios package change was the addition of [email protected], whose…
Two malicious Axios npm releases, versions 1.14.1 and 0.30.4, were published after an attacker used a compromised long-lived classic npm token for the lead maintainer account. The poisoned packages added the hidden dependency plain-crypto-js 4.2.1, whose …
Attackers hijacked the jasonsaayman npm account and published malicious [email protected] and [email protected], adding [email protected] solely to run a postinstall dropper. The package contacted sfrclak[.]com:8000 and installed platform-specific RAT payloads …
KMSEC found two npm packages published by jaime9008 distributing an obfuscated loader for PylangGhost, a RAT the excerpt says Cisco Talos attributed to FAMOUS CHOLLIMA. Malicious versions of react-refresh-update and @jaime9008/math-service used runtime.js…
Socket uncovered 26 malicious npm packages tied to North Korea’s Contagious Interview activity and assessed the tradecraft as consistent with FAMOUS CHOLLIMA. The packages were typosquats of widely used developer libraries and executed install scripts tha…
A malicious npm package named bigmathix impersonated the legitimate big.js library and introduced malicious version 1.0.2 after two benign releases and more than 20 days of dwell time. The package, published by jacksonroman338, used an obfuscated multi-st…
Socket tracks North Korea’s Contagious Interview operation expanding its npm supply-chain activity with at least 197 additional malicious packages and more than 31,000 downloads, targeting blockchain and Web3 developers through fake interviews and test as…
JFrog found a two-part npm cryptocurrency stealer that paired a benign-looking Ethereum address validation package with a malicious transitive dependency. The visible package exported ordinary address-checking functions, but dynamically imported aes-core-…
Socket tracks North Korea’s Contagious Interview operation as a weekly, wave-based abuse of npm, identifying more than 338 malicious packages with over 50,000 downloads and 25 still live at publication time. The campaign uses fake recruiter personas, Link…
Socket reports that North Korean Contagious Interview operators expanded their software supply-chain activity with 67 malicious npm packages, including 28 tied to the newly identified XORIndex loader and 39 new HexEval packages. XORIndex collects host met…
Socket attributes a continuing North Korean Contagious Interview supply-chain campaign to 35 malicious npm packages published across 24 accounts, including six packages that remained live and had more than 4,000 downloads. The packages target developers a…
Veracode describes a renewed North Korean npm malware campaign that targets developers with malicious packages disguised as logging, validation, React, or utility libraries. The packages appear designed for social-engineering workflows in which a target r…
Socket identifies 11 additional malicious npm packages tied to North Korea’s Contagious Interview operation and Lazarus-linked infrastructure, expanding earlier BeaverTail activity with new RAT loader behavior. The packages impersonated developer utilitie…
Lazarus is reported to have distributed six malicious npm packages through typosquatting and package impersonation, exposing developers to credential theft, sensitive data collection, backdoor installation, and malicious code execution during software bui…
North Korea’s Lazarus Group continues to infiltrate the npm ecosystem, deploying six new malicious packages designed to compromise developer environments, steal credentials, extract cryptocurrency data, and deploy a backdoor. The secondary payload (SHA256…
A fake Web3 recruiting process led a freelance developer to run a project that installed malware through an unfamiliar npm package named process-log. The package started a second Node.js server, fetched obfuscated JavaScript from npoint.io JSON endpoints,…
SecurityScorecard’s STRIKE team attributes Operation Marstech Mayhem to Lazarus Group and describes Marstech1 as an implant aimed at software developers and cryptocurrency wallets through manipulated open-source repositories. Attackers used fake GitHub re…
Socket found a malicious npm package, postcss-optimizer, that impersonated the legitimate postcss library and contained BeaverTail malware linked to North Korean Contagious Interview activity within the broader Lazarus ecosystem. The package targeted deve…
Phylum reports a renewed August 2024 wave of North Korea-aligned npm activity aimed at developers, with packages including temp-etherscan-api, ethersscan-api, telegram-con, qq-console, helmet-validate, and sass-notification. The qq-console and related pac…
A July 2024 software supply-chain roundup notes that North Korean threat actors published multiple malicious npm packages targeting developers, with activity reportedly continuing for about a year. Some of the npm packages mimicked trusted or popular pack…
Checkmarx describes a nearly year-long North Korean campaign that publishes malicious npm packages to compromise developers, with a July 2024 surge reported by multiple security firms. The packages are often short lived because the actors unpublish them q…
Datadog found two npm packages, harthat-hash and harthat-api, published on July 7, 2024 by nagasiren978, that used preinstall scripts to run malicious JavaScript on installation. The packages copied legitimate node-config code but added deference.js and p…
Stacklok reports that the npm package next-react-notify, published on 22 July 2024, copied the popular call-bind package and added a preinstall script that executed and deleted a downloader. On Windows systems, the script wrote execu.bat and yui.ps1, fetc…
Phylum linked new npm publications on 23 April 2024 to a previously reported North Korea-attributed campaign against open-source package ecosystems. The packages react-dom-production-script and hardhat-daemon used a preinstall hook to run deference.js as …
Phylum reports that a crypto-themed npm package campaign first described in November remained active, with nearly two dozen additional packages identified through December 2023. The packages download a remote binary during installation, decrypt and execut…
QiAnXin analyzes downloader samples tied to an npm package supply-chain poisoning incident that it assesses as likely Lazarus based on code overlap with historical Lazarus samples and the group's prior use of supply-chain attacks. The loader decrypts embe…
Phylum found a crypto-themed npm supply-chain campaign after its detector flagged the puma-com package on October 30, 2023, then connected four more packages to the same activity. The Windows-only preinstall script writes and runs batch and PowerShell fil…
ReversingLabs found additional malicious npm packages linked to the JumpCloud supply chain incident and cryptocurrency-sector targeting, including btc-api-node and packages impersonating or resembling legitimate crypto-related modules. The packages commun…
Phylum linked a June 2023 npm supply-chain campaign to GitHub’s high-confidence attribution to Jade Sleet, also known as TraderTraitor, a group operating in support of North Korean objectives. The campaign targeted personal accounts of technology-firm emp…
ReversingLabs described Operation Brainleeches as a malicious npm campaign in which more than a dozen packages supported both Microsoft 365 phishing and software supply-chain compromise. The first tranche hosted files for phishing emails that launched fak…
Phylum observed a coordinated npm supply-chain campaign in which malicious packages were published in pairs that had to run sequentially on the same host. The first package used a preinstall hook to install sync-request, contact an attacker server, and wr…