Axios npm Supply-Chain Attack Deployed Cross-Platform RATs; Hunt.io Links It to TA444/BlueNoroff

· Original article ↗

Summary

Hunt.io details malicious Axios npm releases that installed cross-platform RATs through an obfuscated dropper, and attributes the campaign to TA444/BlueNoroff based on malware and infrastructure overlaps.

Key points

  • The article says attackers compromised Axios maintainer jasonsaayman’s npm account and published malicious axios@1.14.1 and axios@0.30.4 releases.
  • A staged plain-crypto-js@4.2.1 dependency used an obfuscated postinstall dropper to detect the operating system, deploy a platform-specific RAT, and remove installation traces.
  • The RATs for Windows, macOS, and Linux shared C2 commands for remote script execution, file browsing, binary deployment, and termination; Windows also established Registry Run-key persistence.
  • The reported C2 was sfrclak.com at 142.11.206.73 over HTTP port 8000. The article provides related file hashes, host artifacts, and network indicators.
  • Hunt.io attributes the campaign to TA444/BlueNoroff, citing shared infrastructure indicators and classifying the macOS RAT as NukeSped.
  • The article recommends treating systems that installed the malicious versions as compromised, checking for indicators, rotating accessible credentials and keys, and reviewing dependency-install practices.

Article Details

Attack Vectors
  • The attacker compromised maintainer jasonsaayman's npm account, changed its registered email, and manually published malicious axios@1.14.1 and axios@0.30.4 outside the legitimate CI/CD pipeline.
  • The attacker first published clean plain-crypto-js@4.2.0, then weaponized v4.2.1 approximately 18 hours later with a postinstall hook executing setup.js.
  • The obfuscated Node.js dropper detected the operating system and downloaded a platform-specific RAT: PowerShell on Windows, Python on Linux, or a compiled Mach-O binary on macOS.
  • Windows delivery renamed PowerShell to wt.exe and used hidden VBScript and cmd.exe execution. Windows persistence re-downloaded the RAT into memory through a Registry Run key.
  • The RATs accepted remote script execution and filesystem-browsing commands. Windows supported injection into cmd.exe, while macOS supported binary dropping and ad-hoc signing. The Linux binary-drop handler was broken by an undefined variable.
  • The dropper deleted itself and the malicious package manifest, then installed a clean v4.2.0 manifest stub to conceal the infection.
Defensive Notes
  • Treat systems that installed axios@1.14.1 or axios@0.30.4 as compromised and rotate accessible credentials, API keys, SSH keys, and tokens.
  • Inspect network logs for the reported C2 domain and IP on port 8000. Monitor outbound HTTP POST traffic using the fake IE8 User-Agent mozilla/4.0 (compatible; msie 8.0; windows nt 5.1; trident/4.0).
  • Check for /Library/Caches/com.apple.act.mond, %PROGRAMDATA%\wt.exe, %PROGRAMDATA%\system.bat, and /tmp/ld.py.
  • Monitor Registry Run key changes using the value name MicrosoftUpdate. On affected Windows systems, remove that value and delete system.bat and wt.exe.
  • Detect codesign --force --deep --sign - launched by non-standard parent processes on macOS.
  • Flag processes launched by npm postinstall hooks that make outbound network connections.
  • Pin dependency versions in package-lock.json, use npm ci in CI/CD pipelines, and use --ignore-scripts when postinstall hooks are unnecessary.
  • Integrate dependency scanning into build workflows, monitor publications for missing OIDC Trusted Publisher signatures, and restrict outbound HTTP on non-standard ports.

Indicators of compromise

TypeIndicatorContext
DOMAINa0info[.]v6[.]armyJustJoin landing-page domain listed as related TA444/BlueNoroff infrastructure.
DOMAINsfrclak[.]comDefanged C2 domain listed in the network indicators.
EMAILifstap@proton[.]meEmail address set by the attacker on the compromised npm maintainer account.
EMAILnrwise@proton[.]meAttacker account address used to publish the staged plain-crypto-js package.
IPV4108[.]174[.]194[.]196Related infrastructure sharing the JustJoin server's SSH key; the article identifies it as phishing infrastructure based on open email ports.
IPV4108[.]174[.]194[.]44Related infrastructure sharing an SSH key fingerprint with the JustJoin server; reported active at the time of writing.
IPV4142[.]11[.]206[.]73Defanged C2 IP used for infrastructure pivoting and listed in the IOC section.
IPV423[.]254[.]167[.]216Reported TA444/BlueNoroff JustJoin landing-page server sharing a unique HTTP ETag with the Axios C2.
SHA107d889e2dadce6f3910dcbc253317d28ca61c766Package SHA listed for malicious plain-crypto-js@4.2.1; reproduced exactly despite its nonstandard length.
SHA1d6f3f62fd3b9f5432f5782b62d8cfd5247d5ee71Package SHA listed for malicious axios@0.30.4; reproduced exactly despite its nonstandard length.
SHA256506690fcbd10fbe6f2b85b49a1fffa9d984c376c25ef6b73f764f670e932cab4SHA-256 of the macOS Mach-O RAT.
SHA256617b67a8e1210e4fc87c92d1d1da45a2f311c08d26e89b12307cf583c900d101SHA-256 of the Windows PowerShell RAT.
SHA256e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09SHA-256 of the setup.js dropper.
SHA256e1f6b7f621a391a9d26e9a196974f3e2cc1ce8b4d8f73a14b2e8cb0f2a40289fSSH key fingerprint shared across three servers attributed by the article to coordinated DPRK infrastructure; not a malware file hash.
SHA256f7d335205b8d7b20208fb3ef93ee6dc817905dc3ae0c10a0b164f4e7d07121cdSHA-256 of the Windows Stage-1 launcher.
SHA256fcb81618bb15edfdedfb638b4c08a2af9cac9ecfa551af135a8402bf980375cfSHA-256 of the Linux Python RAT.
URLhxxp[:]//sfrclak[.]com:8000/C2 base URL recovered from the dropper's encrypted string table.
URLhxxp[:]//sfrclak[.]com:8000/6202033Payload download and RAT C2 endpoint shown in the Linux delivery command.

MITRE ATT&CK

T1027 · Obfuscated Files or InformationThe dropper concealed its strings and payload scripts using XOR with OrDeR_7077 and reversed Base64.T1033 · System Owner/User DiscoveryThe Windows and Linux RATs collected the current username as part of their system profiles.T1036.005 · Match Legitimate Resource Name or LocationThe Windows persistence value MicrosoftUpdate and macOS path com.apple.act.mond were selected to resemble legitimate system components.T1055 · Process InjectionThe Windows peinject handler loaded a .NET DLL through Reflection and invoked Extension.SubRoutine.Run2 to inject a payload into cmd.exe.T1057 · Process DiscoveryThe RATs enumerated processes through WMI on Windows, /proc on Linux, and ps -eo user,pid,command on macOS.T1059.001 · PowerShellWindows delivery and RAT commands executed PowerShell using execution-policy bypass, ScriptBlock, and EncodedCommand.T1059.002 · AppleScriptmacOS delivery and remote script commands executed AppleScript through osascript.T1059.003 · Windows Command ShellWindows delivery launched hidden cmd.exe, and system.bat provided the persistence launcher.T1059.004 · Unix ShellLinux delivery used an inline shell command, while macOS used /bin/zsh and supported /bin/sh -c for remote commands.T1059.005 · Visual BasicWindows delivery wrote a VBScript using WScript.Shell to launch the download and execution chain.T1059.006 · PythonThe Linux RAT ran through python3 and executed C2-supplied Python code using python3 -c.T1059.007 · JavaScriptThe malicious dependency's postinstall hook ran the JavaScript dropper with node setup.js.T1070.004 · File DeletionThe dropper deleted setup.js and the malicious package.json; delivery and command handlers also removed temporary scripts.T1071.001 · Web ProtocolsAll three RATs exchanged HTTP POST beacons and JSON command responses with the C2 on port 8000.T1082 · System Information DiscoveryThe RATs collected hostname, OS version, architecture, timezone, boot time, installation time, and hardware information.T1083 · File and Directory DiscoveryInitial beacons included user-directory listings, and the rundir command returned file and directory metadata.T1105 · Ingress Tool TransferThe dropper downloaded OS-specific RAT payloads from the C2, and Windows persistence downloaded a fresh RAT after reboot.T1132.001 · Standard EncodingAll three RAT variants Base64-wrapped their JSON request bodies before sending them to the C2.T1140 · Deobfuscate/Decode Files or InformationAt runtime, the dropper reversed and Base64-decoded its string table, then applied XOR to recover C2 details and payload scripts.T1195.002 · Compromise Software Supply ChainThe compromised npm maintainer account published malicious Axios releases that introduced a dependency with a postinstall dropper.T1547.001 · Registry Run Keys / Startup FolderThe Windows RAT registered system.bat under the current user's Registry Run key with the value name MicrosoftUpdate.T1553.002 · Code SigningThe macOS binary-drop handler applied codesign --force --deep --sign - before execution, described by the article as a Gatekeeper bypass.T1564.001 · Hidden Files and DirectoriesThe macOS handler wrote payload binaries with dot-prefixed filenames, and Windows created a hidden persistence batch file.T1564.003 · Hidden WindowWindows delivery used WScript.Shell and PowerShell -w hidden to execute without visible windows.

People

Threat Actors

Malware

Vendors

Products

AxiosAxios pulls over 37 million weekly downloads on npm. That kind of reach makes it a prime target, and someone took the shot. The npm account belonging to the library's primary maintainer, jasonsaayman, was compromisedLinuxRAT. A compiled Mach-O binary on macOS, a fileless PowerShell implant on Windows, or a Python script on Linux. Seconds after the RAT is running, the dropper wipes itself and swaps the malicious package.json for amacOSThe dropper checks the victim's OS and pulls down a platform-specific RAT. A compiled Mach-O binary on macOS, a fileless PowerShell implant on Windows, or a Python script on Linux. Seconds after the RAT is running, theMicrosoft Windowspulls down a platform-specific RAT. A compiled Mach-O binary on macOS, a fileless PowerShell implant on Windows, or a Python script on Linux. Seconds after the RAT is running, the dropper wipes itself and swaps theNode.jspicture came into focus. The decrypted values revealed the C2 server URL (http://sfrclak.com:8000/), the Node.js modules the dropper needs to import (child_process for shell execution, os for platform detection, fs fornpmAxios pulls over 37 million weekly downloads on npm. That kind of reach makes it a prime target, and someone took the shot. The npm account belonging to the library's primary maintainer, jasonsaayman, was compromisedPowerShellthe victim's OS and pulls down a platform-specific RAT. A compiled Mach-O binary on macOS, a fileless PowerShell implant on Windows, or a Python script on Linux. Seconds after the RAT is running, the dropper wipes

Tools

Countries

Industries

Related Articles