---
id: "2039130814479204630"
created_at: "2026-04-01T00:00:46+00:00"
lang: en
in_reply_to: null
in_reply_to_user: null
thread_root: "2039130814479204630"
kind: retweet
original_id: "2038893149217562954"
external_status: ok
---

RT @vineetwts: This is how the Axios's Supply Chain Attack happened

- Lead maintainer's npm account was hacked
- Hacker obtained the npm a…

---

### Original `2038893149217562954` V @vineetwts

This is how the Axios's Supply Chain Attack happened

- Lead maintainer's npm account was hacked
- Hacker obtained the npm access token
- Changed registered mail to `ifstap@proton.me` 
- Published directly via CLI, bypassing CI/CD checks
- Throwaway account pre-staged attack (18h prior)
- plain-crypto-js@4.2.0 used as a clean decoy
- plain-crypto-js@4.2.1 → actual malicious payload 
- Triggered via npm postinstall hook
- Installed cross-platform RAT:
- Connected to C2 → http://sfrclak.com:8000
- Self-destructed after execution
