Malicious axios NPM Supply Chain C2 Domain Resolution

PremiumReviewedSigma · High · v1
Product
windows
Category
dns_query
Author
HuntRule
Published
2026-09-14
Updated
2026-09-14

ATT&CK techniques

Initial Access → C2
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. Exfiltration

  12. Impact

What it detects

This rule detects DNS resolution of sfrclak.com, the command-and-control domain contacted by the trojanized axios and plain-crypto-js npm packages after their postinstall scripts execute. The malware sends base64-encoded JSON beacons over HTTP to this host roughly every 60 seconds to fetch second-stage per-OS payloads. Detecting the lookup is important because it surfaces build and developer machines compromised through the npm supply chain.

Related detections9 linkedT1105 — drag to rearrange
Malicious Curl Download From C2 CAPTCHA Path via Process Creation
Malicious C2 Download Embedding Host Reconnaissance in URL
Suspicious File Upload via curl Multipart Form
Suspicious Network Download Spawned by Node.js During Package Install
Possible GCleaner Loader C2 Check-in via cpa ping php Endpoint via proxy
TAG-144 Payload Staging via MyCustomAgent User-Agent (via proxy)
Possible NetHealth Implant C2 Beacon URI Pattern
LightSpy macOS Implant PID File Creation in Users Shared
Linux process chain for Axios NPM compromise: curl download with nohup and python3
Malicious axios NPM Supply Chain C2 Domain Resolution
Pivot detection · T1105 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.