Windows Process Tree for Axios npm Supply-Chain RAT Droppers (cscript, curl, PowerShell)

Alerts on the Windows process/command-line pattern consistent with the Axios npm compromise execution and C2 fetch.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2026-04-01
Updated
2026-07-31

ATT&CK techniques

Initial Access → C2
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. Exfiltration

  11. Impact

What it detects

This rule identifies a specific Windows execution chain tied to the Axios npm supply-chain compromise, where a process tree uses cscript/vbs in a Temp-driven execution flow, followed by network contact via curl and a PowerShell invocation masquerading as Windows Terminal. Attackers leverage this staged chain to run a malicious postinstall payload, fetch platform-specific RAT components from attacker infrastructure, and remove evidence by deleting the script and modifying package artifacts. Detection relies on Windows process creation telemetry, including parent/child image paths and command-line substrings that match the described indicators and C2 URL.

Related detections9 linkedT1105 — drag to rearrange
Malicious Kimsuky VBE Payload Download via Curl to AppData and Execution (via process_creation)
Malicious SCMBanker ClickFix Payload Fetch via Curl Piped to Cmd
Suspicious Network Download Spawned by Node.js During Package Install
Suspicious Aimmy Cheat Loader Executing Renamed LuaJIT Launcher via process_creation
Malicious WSH Script Execution from WebDAV Share (via process_creation)
Suspicious Cmd Using Curl to Download and Execute Payload (via process_creation)
Linux process chain for Axios NPM compromise: curl download with nohup and python3
macOS: Axios NPM compromise file creation via curl and node indicators
macOS: Detect Axios malicious npm execution chain using osascript, curl download, and cleanup
Windows Process Tree for Axios npm Supply-Chain RAT Droppers (cscript, curl, PowerShell)
Pivot detection · T1105 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.