Linux File Drop Indicator for Axios NPM Supply-Chain Compromise (curl to /tmp/ld.py)

Alerts on Linux file creation of /tmp/ld.py by a /curl process, consistent with automated payload staging.

FreeUnreviewedSigmahighv1
title: Linux File Drop Indicator for Axios NPM Supply-Chain Compromise (curl to /tmp/ld.py)
id: 152686e1-7edb-4633-bcd3-08d2f43fadb9
status: experimental
description: This rule flags Linux file creation where a process image ends with /curl and the created file is /tmp/ld.py. Such a pattern can indicate automated download-and-drop behavior consistent with supply-chain payload staging. It relies on file event telemetry that includes the creating process path (Image) and the target created path (TargetFilename).
references:
  - https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan
  - https://www.derp.ca/research/axios-npm-supply-chain-rat/
  - https://www.trendmicro.com/zh_hk/research/26/c/axios-npm-package-compromised.html
  - https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections
  - https://www.virustotal.com/gui/file/e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2026/Malware/Axios-NPM-Compromise/file_event_lnx_axios_npm_compromise_indicators.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2026-04-01
tags:
  - attack.initial-access
  - attack.t1195.002
  - attack.command-and-control
  - attack.t1105
  - detection.emerging-threats
logsource:
  category: file_event
  product: linux
detection:
  selection:
    Image|endswith: /curl
    TargetFilename: /tmp/ld.py
  condition: selection
falsepositives:
  - Highly unlikely
level: high
license: DRL-1.1
related:
  - id: b7cb840c-11f6-47f7-b3ef-5524739c9077
    type: derived

What it detects

This rule flags Linux file creation where a process image ends with /curl and the created file is /tmp/ld.py. Such a pattern can indicate automated download-and-drop behavior consistent with supply-chain payload staging. It relies on file event telemetry that includes the creating process path (Image) and the target created path (TargetFilename).

Known false positives

  • Highly unlikely

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.