DNS queries to known malicious C2 domains from axios/plain-crypto-js npm compromise indicators
Alerts on DNS queries to known malicious C2 domains tied to an Axios npm supply-chain compromise.
- Category
- dns
- Author
- Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2026-04-01
- Updated
- 2026-07-31
ATT&CK techniques
C2Recon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact
What it detects
This rule flags DNS traffic where endpoints attempt to resolve specific domains identified as command-and-control infrastructure tied to the axios/plain-crypto-js npm supply chain compromise. Attackers rely on resolving these domains to establish outbound communication for follow-on payload behavior. The detection relies on DNS query telemetry matching the configured suspicious domain names.
Reporting behind it
- stepsecurity.iohttps://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan
- derp.cahttps://www.derp.ca/research/axios-npm-supply-chain-rat/
- trendmicro.comhttps://www.trendmicro.com/zh_hk/research/26/c/axios-npm-package-compromised.html
- elastic.cohttps://www.elastic.co/security-labs/axios-supply-chain-compromise-detections
- virustotal.comhttps://www.virustotal.com/gui/file/e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09
- huntress.comhttps://www.huntress.com/blog/supply-chain-compromise-axios-npm-package
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2026/Malware/Axios-NPM-Compromise/net_dns_axios_npm_compromise_indicator.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: DNS queries to known malicious C2 domains from axios/plain-crypto-js npm compromise indicators
id: 7ba3fcaf-1dad-4ab7-9705-32ae9e21f8dd
status: experimental
description: This rule flags DNS traffic where endpoints attempt to resolve specific domains identified as command-and-control infrastructure tied to the axios/plain-crypto-js npm supply chain compromise. Attackers rely on resolving these domains to establish outbound communication for follow-on payload behavior. The detection relies on DNS query telemetry matching the configured suspicious domain names.
references:
- https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan
- https://www.derp.ca/research/axios-npm-supply-chain-rat/
- https://www.trendmicro.com/zh_hk/research/26/c/axios-npm-package-compromised.html
- https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections
- https://www.virustotal.com/gui/file/e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09
- https://www.huntress.com/blog/supply-chain-compromise-axios-npm-package
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2026/Malware/Axios-NPM-Compromise/net_dns_axios_npm_compromise_indicator.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2026-04-01
tags:
- attack.command-and-control
- attack.t1071.001
- attack.t1568
- detection.emerging-threats
logsource:
category: dns
detection:
selection:
query:
- sfrclak.com
- calltan.com
- callnrwise.com
condition: selection
falsepositives:
- Unlikely
level: high
license: DRL-1.1
related:
- id: 73e5d24f-493f-4092-bd2f-c72cabda40ee
type: derived