ZshBucket is a malware family uniquely associated in the provided reporting with the DPRK-linked threat actor STARDUST CHOLLIMA. In the cited March 31, 2026 Axios npm supply-chain compromise, attackers used stolen maintainer credentials to distribute updated, platform-specific ZshBucket variants via the widely used Axios package. The observed variants targeted Linux, macOS, and Windows, expanding beyond previously observed macOS-only samples. Across platforms, the malware used a common JSON-based messaging protocol and retained prior ZshBucket functionality for profiling the user and host operating system and transmitting collected information. Reported capabilities included injecting binary payloads, executing arbitrary scripts and commands, enumerating the file system, and remotely terminating the implant; these capabilities replaced earlier, simpler download-and-execute behavior. The malware communicated with command-and-control infrastructure at sfrclak[.]com, hosted on 142.11.206[.]73. The domain shared server characteristics with 23.254.203[.]244, identified as known STARDUST CHOLLIMA infrastructure active since December 2025, and with 23.254.167[.]216, previously used as C2 for FAMOUS CHOLLIMA’s InvisibleFerret malware in May 2025. The domain was registered through Hostwinds. CrowdStrike attributed the Axios activity to STARDUST CHOLLIMA with moderate confidence based on ZshBucket’s exclusive association with that actor and infrastructure overlaps, while noting some overlap with FAMOUS CHOLLIMA. The campaign potentially affected developer environments broadly because Axios was downloaded more than 100,000 times per week, and the likely motive was assessed as financial gain or currency generation, consistent with STARDUST CHOLLIMA’s history of targeting cryptocurrency holders and fintech organizations through npm and PyPI supply-chain compromises. Reported indicators of compromise include communication with sfrclak[.]com, 142.11.206[.]73, 23.254.203[.]244, and 23.254.167[.]216.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Analysts noted that the attackers deployed updated variants of a malware family called ZshBucket — a tool exclusively tied to STARDUST CHOLLIMA — targeting Linux, macOS, and Windows systems.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
On March 31, 2026, a threat actor used stolen maintainer credentials to compromise the widely used HTTP client library Axios Node Package Manager (npm) package and deploy platform-specific ZshBucket variants.
The updated ZshBucket variants now use a common JSON-based messaging protocol that works consistently across Linux, macOS, and Windows systems. This standardization allows operators to manage all infected machines through one unified communication channel. The malware connects to a command-and-control server at the domain sfrclak[.]com
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ZshBucket is a cross-platform malware family tied to STARDUST CHOLLIMA. In this campaign, updated variants used a JSON-based messaging protocol across Linux, macOS, and Windows, connected to C2 infrastructure, and allowed operators to inject binary payloads, execute arbitrary scripts and commands, enumerate the file system, and remotely terminate the implant.
A cross-platform implant/backdoor used in a supply chain compromise via the Axios npm package. It targets Linux, macOS, and Windows systems, profiles the user and host, sends collected information to C2, and supports operator commands to inject binary payloads, execute arbitrary scripts and commands, enumerate the file system, and remotely terminate the implant.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.