Malicious axios NPM Supply Chain Persistence via MicrosoftUpdate Run Key

PremiumReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-09-15
Updated
2026-09-15

ATT&CK techniques

Initial Access → Priv Esc
  1. Recon

  2. Resource Dev

  3. Execution

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects creation of a Run key value named MicrosoftUpdate under the Windows CurrentVersion Run path, a persistence mechanism dropped by the trojanized axios npm packages through their postinstall setup.js script. The masquerading value name mimics a legitimate Microsoft update task while pointing to attacker second-stage code that beacons to sfrclak.com. Detecting this key is important because it establishes reboot-persistent execution of supply-chain malware on developer hosts.

Related detections9 linkedT1547.001 — drag to rearrange
Malicious Registry Run Key Persistence Masquerading as MicrosoftUpdate
Suspicious Node.js Spawning Script Interpreter for Dropped Payload
Malicious Node.js Execution of Hidden .claude Setup Script
Malicious axios NPM Supply Chain C2 Domain Resolution
Malicious Run Key Persistence Referencing DLL in User Documents
PlugX Persistence via Run Key Named AAM Updatevlm
Suspicious Autorun Registry Persistence via sausageLoop Run Key
Malicious BabyLockerKZ Run Key Persistence
Suspicious Run Key Persistence Pointing To User-Writable Path
Malicious axios NPM Supply Chain Persistence via MicrosoftUpdate Run Key
Pivot detection · T1547.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.