macOS: Axios NPM compromise file creation via curl and node indicators

Alerts on macOS file events matching curl and node staging paths linked to an Axios npm compromise pattern.

FreeReviewedSigma · High · v5
Product
macos
Category
file_event
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2026-04-01
Updated
2026-07-31

ATT&CK techniques

Initial Access → C2
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. Exfiltration

  12. Impact

What it detects

This rule flags file creation activity on macOS that matches a specific pattern of command execution artifacts: a curl process writing to a cache-like path and a node process creating a transient file. Such behavior can indicate installation-stage activity associated with malicious npm package compromise workflows, where scripts drop or stage additional payloads. It relies on file event telemetry containing the creating process image path suffix and the target filename involved in the writes.

Related detections9 linkedT1105 — drag to rearrange
Suspicious Network Download Spawned by Node.js During Package Install
Linux process chain for Axios NPM compromise: curl download with nohup and python3
macOS: Detect Axios malicious npm execution chain using osascript, curl download, and cleanup
Linux file creation via curl to /tmp/ld.py (Axios NPM compromise indicators)
Windows Process Tree for Axios npm Supply-Chain RAT Droppers (cscript, curl, PowerShell)
Suspicious Remote Script Transfer via Bitsadmin (via process_creation)
Suspicious PowerShell Download Cradle via ClickFix Fake CAPTCHA (via process_creation)
Suspicious Child Process Spawned by Python Interpreter via Process Creation
Malicious Curl MSI Download to ProgramData via Process Creation
macOS: Axios NPM compromise file creation via curl and node indicators
Pivot detection · T1105 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.