macOS: Detects Axios npm compromise process chain using osascript, curl download, and cleanup

Flags macOS command-line patterns showing osascript execution plus npm package download and staged file cleanup.

FreeUnreviewedSigmahighv1
title: "macOS: Detects Axios npm compromise process chain using osascript, curl download, and cleanup"
id: 17312bb9-8bc5-4056-a201-1244570b3b2a
status: experimental
description: "This rule matches a macOS execution sequence consistent with a compromised npm package: osascript launched in a nohup context, a curl request to packages.npm.org followed by a write into a specific Apple cache path, and subsequent removal of a staging directory. This matters because supply-chain tampering can lead to remote access payload delivery, persistence preparation, and execution on developer or build systems. It relies on process creation telemetry capturing the CommandLine content for osascript, curl, and rm operations."
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
references:
  - https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan
  - https://www.derp.ca/research/axios-npm-supply-chain-rat/
  - https://www.trendmicro.com/zh_hk/research/26/c/axios-npm-package-compromised.html
  - https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections
  - https://www.virustotal.com/gui/file/e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2026/Malware/Axios-NPM-Compromise/proc_creation_macos_axios_npm_compromise_indicators.yml
date: 2026-04-01
tags:
  - attack.initial-access
  - attack.t1195.002
  - attack.execution
  - attack.command-and-control
  - attack.t1059.002
  - attack.t1059.004
  - attack.t1105
  - detection.emerging-threats
logsource:
  category: process_creation
  product: macos
detection:
  selection_osascript:
    CommandLine|contains|all:
      - "nohup "
      - "osascript "
      - /tmp/6202033
  selection_curl_download:
    CommandLine|contains|all:
      - "curl "
      - packages.npm.org/product
      - /Library/Caches/com.apple.act.mond
  selection_cleanup:
    CommandLine|contains|all:
      - "rm "
      - "-rf "
      - /tmp/6202033
  condition: 1 of selection_*
falsepositives:
  - Unlikely
level: high
license: DRL-1.1
related:
  - id: a09ee860-31b3-4586-8a68-0ebd74ce0e5f
    type: derived

What it detects

This rule matches a macOS execution sequence consistent with a compromised npm package: osascript launched in a nohup context, a curl request to packages.npm.org followed by a write into a specific Apple cache path, and subsequent removal of a staging directory. This matters because supply-chain tampering can lead to remote access payload delivery, persistence preparation, and execution on developer or build systems. It relies on process creation telemetry capturing the CommandLine content for osascript, curl, and rm operations.

Known false positives

  • Unlikely

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.