macOS: File creation indicators for Axios npm supply-chain compromise
Alerts on macOS file events matching curl and node staging paths linked to an Axios npm compromise pattern.
FreeUnreviewedSigmahighv1
macos-file-creation-indicators-for-axios-npm-supply-chain-compromise-2db0458c
title: "macOS: File creation indicators for Axios npm supply-chain compromise"
id: 8997e97f-bee2-4d9a-a031-80baf9bacd9e
status: experimental
description: This rule flags macOS file creation activity consistent with downloading and staging artifacts using a curl process and then running a node process, based on specific image path endings and target file paths. Such staging can be used by attackers to deploy malicious payloads from a compromised npm package and trigger follow-on execution via installer scripts. The detection relies on file event telemetry capturing process image paths and the exact target filenames involved in the observed sequence.
references:
- https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan
- https://www.derp.ca/research/axios-npm-supply-chain-rat/
- https://www.trendmicro.com/zh_hk/research/26/c/axios-npm-package-compromised.html
- https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections
- https://www.virustotal.com/gui/file/e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2026/Malware/Axios-NPM-Compromise/file_event_macos_axios_npm_compromise_indicators.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2026-04-01
tags:
- attack.initial-access
- attack.t1195.002
- attack.command-and-control
- attack.t1105
- detection.emerging-threats
logsource:
category: file_event
product: macos
detection:
selection_curl_download:
Image|endswith: /curl
TargetFilename: /Library/Caches/com.apple.act.mond
selection_node_shell:
Image|endswith: /node
TargetFilename: /tmp/6202033
condition: 1 of selection_*
falsepositives:
- Highly unlikely
level: high
license: DRL-1.1
related:
- id: 2db0458c-05c9-4069-a26f-77becd9c8c13
type: derived
What it detects
This rule flags macOS file creation activity consistent with downloading and staging artifacts using a curl process and then running a node process, based on specific image path endings and target file paths. Such staging can be used by attackers to deploy malicious payloads from a compromised npm package and trigger follow-on execution via installer scripts. The detection relies on file event telemetry capturing process image paths and the exact target filenames involved in the observed sequence.
Known false positives
- Highly unlikely
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.