SILKBELL is an obfuscated JavaScript dropper tracked by Google Threat Intelligence Group as the setup.js postinstall payload used in the March 31, 2026 npm supply chain compromise of axios. In the attack, malicious axios versions 1.14.1 and 0.30.4 introduced the dependency plain-crypto-js@4.2.1, whose postinstall hook automatically executed SILKBELL during npm installation. SILKBELL used a two-layer encoding scheme combining reversed Base64 and XOR, with reporting that the XOR key was "OrDeR_7077" and constant 333, and dynamically loaded Node.js modules such as fs, os, and execSync to hinder static analysis. Its role was to identify the victim operating system and fetch platform-specific next-stage payloads from remote infrastructure, delivering WAVESHAPER.V2 variants for Windows, macOS, and Linux. Reported behaviors included downloading a native C++ Mach-O payload on macOS to /Library/Caches/com.apple.act.mond, a PowerShell-based payload on Windows involving %PROGRAMDATA%\wt.exe and a VBScript launcher, and a Python RAT on Linux to /tmp/ld.py. SILKBELL also performed anti-forensic cleanup by deleting itself, deleting the malicious package.json, and restoring or renaming package metadata to a clean state to remove the postinstall hook. The broader campaign was attributed by GTIG to UNC1069, a financially motivated North Korea-nexus threat actor. Associated network indicators in the campaign included sfrclak[.]com and 142.11.206.73:8000.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Step 5 – Cross-platform RAT installation: The dropper, tracked as SILKBELL, checked the operating system and delivered platform-specific payloads for Windows, macOS, and Linux.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The axios npm package ... was compromised in a supply chain attack ... The attacker had compromised the maintainer account associated with the package and injected a malicious dependency called "plain-crypto-js" that served as a delivery vehicle for a cross-platform remote access trojan (RAT).
On Windows, it searched for powershell.exe, copied it to another path to reduce suspicion, downloaded a PowerShell stage with curl, and ran it with hidden and execution-policy-bypass options.
On macOS, it used bash and curl to place a Mach-O binary in /Library/Caches/com.apple.act.mond, changed file permissions, and launched it through zsh.
This dropper uses a two-layer encoding scheme combining reversed Base64 and XOR cipher (key: "OrDeR_7077", constant: 333) to conceal its command-and-control (C2) URL and execution commands. It dynamically loads Node.js modules ... to evade static analysis.
setup.js attempted to delete itself after dropping the next stage and restore the altered package.json from a stored copy so forensic review would be harder.
After deploying the platform-specific payload, the dropper performs anti-forensic cleanup: it deletes itself, deletes the malicious package.json, and renames a clean stub file (package.md) to package.json
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Obfuscated JavaScript dropper executed via the malicious plain-crypto-js postinstall hook. It decodes and deploys platform-specific payloads, dynamically loads Node.js modules to evade analysis, and performs anti-forensic cleanup by deleting and renaming package files after infection.
An obfuscated JavaScript dropper delivered via a malicious postinstall hook in the compromised axios package. It checks the operating system, downloads and launches platform-specific payloads for Windows, macOS, and Linux, then attempts to delete itself and restore package.json to hinder forensic analysis.
An obfuscated JavaScript dropper delivered via the malicious plain-crypto-js dependency in the Axios supply chain compromise. It retrieves the appropriate next-stage payload depending on whether the victim is running Windows, macOS, or Linux, then performs cleanup to reduce forensic visibility.
An obfuscated JavaScript dropper delivered via the malicious plain-crypto-js dependency. It runs during npm postinstall, detects the host OS, deploys platform-specific payloads, and then self-deletes to reduce forensic visibility.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.