Axios npm Supply-Chain Attack Deployed Cross-Platform RATs; Hunt.io Links It to TA444/BlueNoroff

Summary
Hunt.io details malicious Axios npm releases that installed cross-platform RATs through an obfuscated dropper, and attributes the campaign to TA444/BlueNoroff based on malware and infrastructure overlaps.
Key points
- The article says attackers compromised Axios maintainer jasonsaayman’s npm account and published malicious axios@1.14.1 and axios@0.30.4 releases.
- A staged plain-crypto-js@4.2.1 dependency used an obfuscated postinstall dropper to detect the operating system, deploy a platform-specific RAT, and remove installation traces.
- The RATs for Windows, macOS, and Linux shared C2 commands for remote script execution, file browsing, binary deployment, and termination; Windows also established Registry Run-key persistence.
- The reported C2 was sfrclak.com at 142.11.206.73 over HTTP port 8000. The article provides related file hashes, host artifacts, and network indicators.
- Hunt.io attributes the campaign to TA444/BlueNoroff, citing shared infrastructure indicators and classifying the macOS RAT as NukeSped.
- The article recommends treating systems that installed the malicious versions as compromised, checking for indicators, rotating accessible credentials and keys, and reviewing dependency-install practices.
Article Details
- Attack Vectors
- The attacker compromised maintainer jasonsaayman's npm account, changed its registered email, and manually published malicious axios@1.14.1 and axios@0.30.4 outside the legitimate CI/CD pipeline.
- The attacker first published clean plain-crypto-js@4.2.0, then weaponized v4.2.1 approximately 18 hours later with a postinstall hook executing setup.js.
- The obfuscated Node.js dropper detected the operating system and downloaded a platform-specific RAT: PowerShell on Windows, Python on Linux, or a compiled Mach-O binary on macOS.
- Windows delivery renamed PowerShell to wt.exe and used hidden VBScript and cmd.exe execution. Windows persistence re-downloaded the RAT into memory through a Registry Run key.
- The RATs accepted remote script execution and filesystem-browsing commands. Windows supported injection into cmd.exe, while macOS supported binary dropping and ad-hoc signing. The Linux binary-drop handler was broken by an undefined variable.
- The dropper deleted itself and the malicious package manifest, then installed a clean v4.2.0 manifest stub to conceal the infection.
- Defensive Notes
- Treat systems that installed axios@1.14.1 or axios@0.30.4 as compromised and rotate accessible credentials, API keys, SSH keys, and tokens.
- Inspect network logs for the reported C2 domain and IP on port 8000. Monitor outbound HTTP POST traffic using the fake IE8 User-Agent mozilla/4.0 (compatible; msie 8.0; windows nt 5.1; trident/4.0).
- Check for /Library/Caches/com.apple.act.mond, %PROGRAMDATA%\wt.exe, %PROGRAMDATA%\system.bat, and /tmp/ld.py.
- Monitor Registry Run key changes using the value name MicrosoftUpdate. On affected Windows systems, remove that value and delete system.bat and wt.exe.
- Detect codesign --force --deep --sign - launched by non-standard parent processes on macOS.
- Flag processes launched by npm postinstall hooks that make outbound network connections.
- Pin dependency versions in package-lock.json, use npm ci in CI/CD pipelines, and use --ignore-scripts when postinstall hooks are unnecessary.
- Integrate dependency scanning into build workflows, monitor publications for missing OIDC Trusted Publisher signatures, and restrict outbound HTTP on non-standard ports.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | a0info[.]v6[.]army | JustJoin landing-page domain listed as related TA444/BlueNoroff infrastructure. |
| DOMAIN | sfrclak[.]com | Defanged C2 domain listed in the network indicators. |
ifstap@proton[.]me | Email address set by the attacker on the compromised npm maintainer account. | |
nrwise@proton[.]me | Attacker account address used to publish the staged plain-crypto-js package. | |
| IPV4 | 108[.]174[.]194[.]196 | Related infrastructure sharing the JustJoin server's SSH key; the article identifies it as phishing infrastructure based on open email ports. |
| IPV4 | 108[.]174[.]194[.]44 | Related infrastructure sharing an SSH key fingerprint with the JustJoin server; reported active at the time of writing. |
| IPV4 | 142[.]11[.]206[.]73 | Defanged C2 IP used for infrastructure pivoting and listed in the IOC section. |
| IPV4 | 23[.]254[.]167[.]216 | Reported TA444/BlueNoroff JustJoin landing-page server sharing a unique HTTP ETag with the Axios C2. |
| SHA1 | 07d889e2dadce6f3910dcbc253317d28ca61c766 | Package SHA listed for malicious plain-crypto-js@4.2.1; reproduced exactly despite its nonstandard length. |
| SHA1 | d6f3f62fd3b9f5432f5782b62d8cfd5247d5ee71 | Package SHA listed for malicious axios@0.30.4; reproduced exactly despite its nonstandard length. |
| SHA256 | 506690fcbd10fbe6f2b85b49a1fffa9d984c376c25ef6b73f764f670e932cab4 | SHA-256 of the macOS Mach-O RAT. |
| SHA256 | 617b67a8e1210e4fc87c92d1d1da45a2f311c08d26e89b12307cf583c900d101 | SHA-256 of the Windows PowerShell RAT. |
| SHA256 | e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09 | SHA-256 of the setup.js dropper. |
| SHA256 | e1f6b7f621a391a9d26e9a196974f3e2cc1ce8b4d8f73a14b2e8cb0f2a40289f | SSH key fingerprint shared across three servers attributed by the article to coordinated DPRK infrastructure; not a malware file hash. |
| SHA256 | f7d335205b8d7b20208fb3ef93ee6dc817905dc3ae0c10a0b164f4e7d07121cd | SHA-256 of the Windows Stage-1 launcher. |
| SHA256 | fcb81618bb15edfdedfb638b4c08a2af9cac9ecfa551af135a8402bf980375cf | SHA-256 of the Linux Python RAT. |
| URL | hxxp[:]//sfrclak[.]com:8000/ | C2 base URL recovered from the dropper's encrypted string table. |
| URL | hxxp[:]//sfrclak[.]com:8000/6202033 | Payload download and RAT C2 endpoint shown in the Linux delivery command. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe dropper concealed its strings and payload scripts using XOR with OrDeR_7077 and reversed Base64.T1033 · System Owner/User DiscoveryThe Windows and Linux RATs collected the current username as part of their system profiles.T1036.005 · Match Legitimate Resource Name or LocationThe Windows persistence value MicrosoftUpdate and macOS path com.apple.act.mond were selected to resemble legitimate system components.T1055 · Process InjectionThe Windows peinject handler loaded a .NET DLL through Reflection and invoked Extension.SubRoutine.Run2 to inject a payload into cmd.exe.T1057 · Process DiscoveryThe RATs enumerated processes through WMI on Windows, /proc on Linux, and ps -eo user,pid,command on macOS.T1059.001 · PowerShellWindows delivery and RAT commands executed PowerShell using execution-policy bypass, ScriptBlock, and EncodedCommand.T1059.002 · AppleScriptmacOS delivery and remote script commands executed AppleScript through osascript.T1059.003 · Windows Command ShellWindows delivery launched hidden cmd.exe, and system.bat provided the persistence launcher.T1059.004 · Unix ShellLinux delivery used an inline shell command, while macOS used /bin/zsh and supported /bin/sh -c for remote commands.T1059.005 · Visual BasicWindows delivery wrote a VBScript using WScript.Shell to launch the download and execution chain.T1059.006 · PythonThe Linux RAT ran through python3 and executed C2-supplied Python code using python3 -c.T1059.007 · JavaScriptThe malicious dependency's postinstall hook ran the JavaScript dropper with node setup.js.T1070.004 · File DeletionThe dropper deleted setup.js and the malicious package.json; delivery and command handlers also removed temporary scripts.T1071.001 · Web ProtocolsAll three RATs exchanged HTTP POST beacons and JSON command responses with the C2 on port 8000.T1082 · System Information DiscoveryThe RATs collected hostname, OS version, architecture, timezone, boot time, installation time, and hardware information.T1083 · File and Directory DiscoveryInitial beacons included user-directory listings, and the rundir command returned file and directory metadata.T1105 · Ingress Tool TransferThe dropper downloaded OS-specific RAT payloads from the C2, and Windows persistence downloaded a fresh RAT after reboot.T1132.001 · Standard EncodingAll three RAT variants Base64-wrapped their JSON request bodies before sending them to the C2.T1140 · Deobfuscate/Decode Files or InformationAt runtime, the dropper reversed and Base64-decoded its string table, then applied XOR to recover C2 details and payload scripts.T1195.002 · Compromise Software Supply ChainThe compromised npm maintainer account published malicious Axios releases that introduced a dependency with a postinstall dropper.T1547.001 · Registry Run Keys / Startup FolderThe Windows RAT registered system.bat under the current user's Registry Run key with the value name MicrosoftUpdate.T1553.002 · Code SigningThe macOS binary-drop handler applied codesign --force --deep --sign - before execution, described by the article as a Gatekeeper bypass.T1564.001 · Hidden Files and DirectoriesThe macOS handler wrote payload binaries with dot-prefixed filenames, and Windows created a hidden persistence batch file.T1564.003 · Hidden WindowWindows delivery used WScript.Shell and PowerShell -w hidden to execute without visible windows.
People
Threat Actors
BlueNoroffPresented as the same subgroup as TA444 and attributed by Hunt IO as the operator behind the attack; described as financially motivated and operating under DPRK direction.Lazarus GroupThe article associates the NukeSped classification and nearby previously investigated infrastructure with Lazarus Group, supporting its broader DPRK attribution.TA444Hunt IO attributes the attack to TA444/BlueNoroff based on infrastructure overlaps, malware classification, and operational similarities; the article presents TA444 and BlueNoroff as names for the same subgroup.
Malware
macWebTAdditionally, the binary's internal naming convention references "macWebT", which directly matches malware documented by SentinelOne in their 2023 reporting on TA444/BlueNoroff macOS campaigns. This naming continuityNukeSpedC2 infrastructure links to TA444/BlueNoroff (DPRK) via shared ETag with known JustJoin server, same Hostwinds AS54290 subnet, and NukeSped malware classification
Vendors
HostwindsC2 infrastructure links to TA444/BlueNoroff (DPRK) via shared ETag with known JustJoin server, same Hostwinds AS54290 subnet, and NukeSped malware classificationNamecheapDomain a0info.v6[.]army JustJoin landing page, registered via NameCheapProton MailThe use of Proton Mail addresses (ifstap@proton.me and nrwise@proton.me) for the compromised npm accounts also fits the pattern. DPRK-linked threat actors consistently use privacy-preserving email services for
Products
AxiosAxios pulls over 37 million weekly downloads on npm. That kind of reach makes it a prime target, and someone took the shot. The npm account belonging to the library's primary maintainer, jasonsaayman, was compromisedLinuxRAT. A compiled Mach-O binary on macOS, a fileless PowerShell implant on Windows, or a Python script on Linux. Seconds after the RAT is running, the dropper wipes itself and swaps the malicious package.json for amacOSThe dropper checks the victim's OS and pulls down a platform-specific RAT. A compiled Mach-O binary on macOS, a fileless PowerShell implant on Windows, or a Python script on Linux. Seconds after the RAT is running, theMicrosoft Windowspulls down a platform-specific RAT. A compiled Mach-O binary on macOS, a fileless PowerShell implant on Windows, or a Python script on Linux. Seconds after the RAT is running, the dropper wipes itself and swaps theNode.jspicture came into focus. The decrypted values revealed the C2 server URL (http://sfrclak.com:8000/), the Node.js modules the dropper needs to import (child_process for shell execution, os for platform detection, fs fornpmAxios pulls over 37 million weekly downloads on npm. That kind of reach makes it a prime target, and someone took the shot. The npm account belonging to the library's primary maintainer, jasonsaayman, was compromisedPowerShellthe victim's OS and pulls down a platform-specific RAT. A compiled Mach-O binary on macOS, a fileless PowerShell implant on Windows, or a Python script on Linux. Seconds after the RAT is running, the dropper wipes
Tools
IDA PromacOS RAT: Compiled Mach-O Binary (IDA Pro)npm auditIntegrate dependency scanning tools (Socket.dev, Snyk, npm audit) into build workflowssnykIntegrate dependency scanning tools (Socket.dev, Snyk, npm audit) into build workflowsSocket.devIntegrate dependency scanning tools (Socket.dev, Snyk, npm audit) into build workflows