macOS: Detects Axios npm compromise process chain using osascript, curl download, and cleanup
Flags macOS command-line patterns showing osascript execution plus npm package download and staged file cleanup.
FreeUnreviewedSigmahighv1
macos-detects-axios-npm-compromise-process-chain-using-osascript-curl-download-a-a09ee860
title: "macOS: Detects Axios npm compromise process chain using osascript, curl download, and cleanup"
id: 17312bb9-8bc5-4056-a201-1244570b3b2a
status: experimental
description: "This rule matches a macOS execution sequence consistent with a compromised npm package: osascript launched in a nohup context, a curl request to packages.npm.org followed by a write into a specific Apple cache path, and subsequent removal of a staging directory. This matters because supply-chain tampering can lead to remote access payload delivery, persistence preparation, and execution on developer or build systems. It relies on process creation telemetry capturing the CommandLine content for osascript, curl, and rm operations."
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
references:
- https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan
- https://www.derp.ca/research/axios-npm-supply-chain-rat/
- https://www.trendmicro.com/zh_hk/research/26/c/axios-npm-package-compromised.html
- https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections
- https://www.virustotal.com/gui/file/e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2026/Malware/Axios-NPM-Compromise/proc_creation_macos_axios_npm_compromise_indicators.yml
date: 2026-04-01
tags:
- attack.initial-access
- attack.t1195.002
- attack.execution
- attack.command-and-control
- attack.t1059.002
- attack.t1059.004
- attack.t1105
- detection.emerging-threats
logsource:
category: process_creation
product: macos
detection:
selection_osascript:
CommandLine|contains|all:
- "nohup "
- "osascript "
- /tmp/6202033
selection_curl_download:
CommandLine|contains|all:
- "curl "
- packages.npm.org/product
- /Library/Caches/com.apple.act.mond
selection_cleanup:
CommandLine|contains|all:
- "rm "
- "-rf "
- /tmp/6202033
condition: 1 of selection_*
falsepositives:
- Unlikely
level: high
license: DRL-1.1
related:
- id: a09ee860-31b3-4586-8a68-0ebd74ce0e5f
type: derived
What it detects
This rule matches a macOS execution sequence consistent with a compromised npm package: osascript launched in a nohup context, a curl request to packages.npm.org followed by a write into a specific Apple cache path, and subsequent removal of a staging directory. This matters because supply-chain tampering can lead to remote access payload delivery, persistence preparation, and execution on developer or build systems. It relies on process creation telemetry capturing the CommandLine content for osascript, curl, and rm operations.
Known false positives
- Unlikely
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.