com.apple.act.mond is a macOS remote access trojan (RAT) delivered in a March 31, 2026 npm supply-chain attack involving malicious axios releases (axios@1.14.1 and axios@0.30.4) that added the typosquatted dependency plain-crypto-js@4.2.1. That dependency executed an obfuscated postinstall JavaScript dropper which contacted attacker-controlled infrastructure at http://sfrclak.com:8000/6202033, detected the host OS, and downloaded platform-specific payloads. On macOS, it wrote the RAT to /Library/Caches/com.apple.act.mond. The payload is described as a 657 KB Mach-O universal binary for x86_64 and arm64, compiled with Clang/C++, using libcurl for C2 communications and statically linked nlohmann/json v3.11.3 for JSON handling. The RAT used plain HTTP POST with base64-encoded JSON and the user-agent string "mozilla/4.0 (compatible; msie 8.0; windows nt 5.1; trident/4.0)". Reported command support includes kill, peinject, runscript, and rundir, enabling remote command execution, directory listing, and execution of additional payloads. The macOS variant reportedly lacked persistence mechanisms such as a LaunchAgent, LaunchDaemon, or login item. The broader campaign is associated with compromise of the npm maintainer account jasonsaayman and attacker-controlled infrastructure including sfrclak.com on 142.11.206.73. High-confidence indicators include the file path /Library/Caches/com.apple.act.mond and the associated C2 domain sfrclak.com.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
runscript do_action_scpt() Two modes: direct shell ( subprocess.run(shell=True) ) or Base64 Python script via python3 -c ... PowerShell with 3 execution paths ... /usr/bin/osascript OR shell exec
The second stage is a PowerShell-based RAT that beacons to its C2 every 60 seconds over HTTP using a fake IE8 User-Agent and base64-encoded JSON.
T1036 Masquerading wt.exe mimics Windows Terminal; com.apple.act.mond mimics Apple daemon; packages.npm.org/ prefix in POST body mimics npm registry traffic
The package connects to a Sapphire Sleet-owned domain ( hxxp://sfrclak[.]com ), which fetches a second-stage payload from an actor-controlled server running on port 8000.
T1071.001 Application Layer Protocol: Web Protocols HTTP POST to sfrclak[.]com:8000 with campaign ID 6202033 in URL path
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A macOS remote access trojan delivered via the malicious plain-crypto-js npm dependency. It communicates with its C2 over base64-encoded JSON via HTTP POST, performs host reconnaissance, supports kill, peinject, runscript, and rundir commands, and can drop, ad-hoc sign, and execute payloads on disk.
A macOS Stage 2 compiled C++ remote access trojan delivered by plain-crypto-js. It fingerprints the host, beacons every 60 seconds, supports commands including kill, peinject, runscript, and rundir, and can execute additional payloads, but no built-in persistence was observed.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.