AxiosRAT is a cross-platform remote access trojan deployed in a March 2026 npm software supply-chain compromise involving malicious Axios package releases. The operation abused a phantom dependency that executed during npm post-installation, allowing the malware to run automatically when affected package versions were installed. The campaign targeted Windows, macOS, and Linux environments and was especially dangerous in developer workstations, build systems, and CI/CD pipelines because infection could occur transitively through a trusted dependency.
The malware used an obfuscated JavaScript dropper to identify the host operating system, contact attacker-controlled command-and-control infrastructure, and retrieve platform-specific payloads. On Windows, it launched a PowerShell-based RAT through a VBScript and renamed copy of PowerShell to reduce scrutiny. On macOS, it downloaded and executed a background binary payload. On Linux, it retrieved and launched a detached Python RAT. Observed behavior indicates persistent background execution independent of the original npm install process.
AxiosRAT supported post-compromise remote access and theft of sensitive material from infected environments, including developer and cloud-related secrets such as npm tokens, SSH material, environment variables, and CI/CD credentials. The malware also demonstrated defense-evasion and anti-forensics behavior by deleting or replacing installation artifacts after execution to conceal the malicious dependency and hinder incident response. Telemetry associated with the campaign indicated impact across multiple sectors, including government, finance, healthcare, technology, manufacturing, retail, consulting, entertainment, and utilities.
The intrusion was enabled by compromise of a maintainer account and manual publication of poisoned package versions outside the project’s normal trusted publishing workflow. Related malicious npm packages have been linked to the same infrastructure, indicating a broader pre-staged campaign rather than an isolated package tampering event.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cross-platform remote access trojan delivered via the malicious npm package plain-crypto-js@4.2.1 inserted into poisoned Axios releases. It uses a postinstall dropper (setup.js) to fetch and execute platform-specific second stages on macOS, Windows, and Linux, then deletes its own artifacts and swaps in a clean decoy manifest for anti-forensics.
Cross-platform remote access trojan payload family delivered by the plain-crypto-js npm package. Variants include Linux Python and Windows PowerShell backdoors used for credential theft, data exfiltration, command-and-control, and persistent access.
A cross-platform remote access trojan delivered through malicious Axios npm releases via the phantom dependency plain-crypto-js@4.2.1. It used a postinstall hook to drop platform-specific payloads for macOS, Windows, and Linux, contacted sfrclak[.]com for second-stage content, established persistence/execution, and then performed anti-forensics by deleting setup.js and swapping in clean decoy package files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.