Axios NPM Compromise Indicators - Windows
Detects the specific Windows execution chain and process tree associated with the Axios NPM supply chain compromise. On March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper. The dropper contacted a C2 server, delivered platform-specific payloads, deleted itself, and replaced package.json to evade detection. The attack used cscript.exe (VBScript), curl.exe (C2), and PowerShell masquerading as Windows Terminal.
Detection logic
selection_cscript
ParentImage|endswith:
- \node.exe
- \bun.exe
Image|endswith: \cmd.exe
CommandLine|contains|all:
- cscript
- AppData\Local\Temp
- //nologo && del
- 6202033.vbsselection_curl
Image|endswith:
- \curl.exe
- \powershell.exe
CommandLine|contains: http://sfrclak.comselection_susp_cli
OriginalFileName: PowerShell.EXE
CommandLine|contains: '"C:\ProgramData\wt.exe" -w hidden -ep bypass -file'Condition
1 of selection_*Raw YAML
title: Axios NPM Compromise Indicators - Windows
id: f6c27ecc-d890-4452-80e6-2e274a10e097
status: experimental
description: |
Detects the specific Windows execution chain and process tree associated with the Axios NPM supply chain compromise.
On March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper.
The dropper contacted a C2 server, delivered platform-specific payloads, deleted itself, and replaced package.json to evade detection.
The attack used cscript.exe (VBScript), curl.exe (C2), and PowerShell masquerading as Windows Terminal.
references:
- https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan
- https://thehackernews.com/2026/03/axios-supply-chain-attack-pushes-cross.html?m=1
- https://www.derp.ca/research/axios-npm-supply-chain-rat/
- https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections
- https://www.virustotal.com/gui/file/e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09
author: Swachchhanda Shrawan Poudel (Nextron Systems)
date: 2026-04-01
tags:
- attack.initial-access
- attack.t1195.002
- attack.execution
- attack.command-and-control
- attack.t1059.003
- attack.t1059.005
- attack.t1105
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection_cscript:
ParentImage|endswith:
- '\node.exe'
- '\bun.exe'
Image|endswith: '\cmd.exe'
CommandLine|contains|all:
- 'cscript'
- 'AppData\Local\Temp'
- '//nologo && del'
- '6202033.vbs'
selection_curl:
Image|endswith:
- '\curl.exe'
- '\powershell.exe'
CommandLine|contains: 'http://sfrclak.com'
selection_susp_cli:
OriginalFileName: 'PowerShell.EXE'
CommandLine|contains: '"C:\ProgramData\wt.exe" -w hidden -ep bypass -file'
condition: 1 of selection_*
falsepositives:
- Highly unlikely
level: highFalse positives
- Highly unlikely
References
- https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan
- https://thehackernews.com/2026/03/axios-supply-chain-attack-pushes-cross.html?m=1
- https://www.derp.ca/research/axios-npm-supply-chain-rat/
- https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections
- https://www.virustotal.com/gui/file/e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09
Similar rules
Axios NPM Compromise Indicators - Linux
highlinux · Shares T1195, T1059, T1105
Axios NPM Compromise Indicators - macOS
highmacos · Shares T1195, T1059, T1105
Potential Pikabot Infection - Suspicious Command Combinations Via Cmd.EXE
mediumwindows · Shares T1059, T1105
Command Line Execution with Suspicious URL and AppData Strings
mediumwindows · Shares T1059, T1105