Original ·2038893149217562954· V @vineetwtsThis is how the Axios's Supply Chain Attack happened
- Lead maintainer's npm account was hacked
- Hacker obtained the npm access token
- Changed registered mail to `ifstap@proton.me`
- Published directly via CLI, bypassing CI/CD checks
- Throwaway account pre-staged attack (18h prior)
- plain-crypto-js@4.2.0 used as a clean decoy
- plain-crypto-js@4.2.1 → actual malicious payload
- Triggered via npm postinstall hook
- Installed cross-platform RAT:
- Connected to C2 → http://sfrclak.com:8000
- Self-destructed after execution
RT @vineetwts: This is how the Axios's Supply Chain Attack happened
- Lead maintainer's npm account was hacked
- Hacker obtained the npm a…