RAT is a generic term for remote access trojan malware that enables an attacker to control an infected system remotely. In the context of the 2026 npm supply-chain compromises affecting Axios and the Mastra npm scope, the malware was described as a cross-platform RAT embedded in malicious package releases published after maintainer-account compromise. Those incidents indicate use of the malware as a post-compromise payload within the JavaScript package ecosystem, with execution on developer and server environments that install and run the trojanized packages. Reporting around the Axios incident associated the operation with Sapphire Sleet, a North Korean state-sponsored threat actor. High-confidence details in the available material support remote-control functionality and cross-platform targeting, but do not establish a distinct family name, detailed internal tradecraft, persistence mechanisms, or specific data-theft behaviors for this RAT beyond its role as a remote access payload delivered through software supply-chain compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Sapphire Sleet, a North Korean state sponsored threat actor, compromised the npm maintainer account and published malicious versions (axios@1.14.1 and axios@0.30.4) containing a RAT.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Каждый SDK - потенциальный вектор supply chain атаки... Атакующий модифицирует SDK так, чтобы он выполнял легитимные функции, параллельно собирая данные или предоставляя удалённый доступ.
このキャンペーンについては北朝鮮系脅威アクターによるキャンペーン「Contagious Interview」のひとつであると指摘されています。 ※5 North Korea's Contagious Interview Campaign Spreads Across 5 Ecosystems, Delivering Staged RAT Payloads
While on the call, the threat actor said something on Saayman’s system was out of date and prompted him to install an item to fix the issue – a ploy which Huntress researchers have seen in other social engineering attacks. Unbeknownst to Saayman, the install led to the RAT.
En cada uno de ellos, el troyano realizaba un reconocimiento completo del sistema (directorios, procesos activos, unidades de disco)...
The official Telnyx Python package was replaced with a version containing a three-stage RAT that communicated with an attacker-controlled server at 83[.]142[.]209[.]203.
78 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The content only states that 143 packages 'drop a RAT,' indicating a remote access trojan payload was involved, but provides no specific malware family name or further details.
A remote access trojan was embedded in malicious Axios versions published during the March 2026 npm supply-chain compromise.
A remote access trojan embedded in malicious axios package versions during the March 2026 npm supply chain compromise.
A remote access trojan was reportedly deployed following the hijacking of an npm maintainer account in the axios compromise.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.