Rule Info
Name
Axios NPM Compromise File Creation Indicators - Linux
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects file creation events linked to the Axios NPM supply chain compromise. Axios is a popular JavaScript HTTP client.
On March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper.
Date
2026-04-01 00:00:00
Modified
None
Id
b7cb840c-11f6-47f7-b3ef-5524739c9077
Tags
attack.initial-access attack.t1195.002 attack.command-and-control attack.t1105 detection.emerging-threats
Type
Community Rule
Link to Public Repo
Rule History
Author
Title
Date
Commit
Swachchhanda Shrawan Poudel
Merge PR #5928 from @swachchhanda000 - Add Axios NPM Compromise Indicators Related Rules
2026-04-01
