# Remote Access Trojan

Published articles for Remote Access Trojan.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure

DevFeed: [Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](<https://devfeed.tech/articles/untracked-nightmares-the-threats-hiding-behind-commodity-infrastructure-7757.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/>)

Author: Rem Dudas

Published: 2026-09-09T10:00:55Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [ARKTunnel](<https://devfeed.tech/topics/arktunnel.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>)

Tags: [arktunnel](<https://devfeed.tech/tags/arktunnel.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [c2](<https://devfeed.tech/tags/c2.md>), [cl-cri-1171](<https://devfeed.tech/tags/cl-cri-1171.md>), [cybercrime](<https://devfeed.tech/tags/cybercrime.md>), [docro-hijacker](<https://devfeed.tech/tags/docro-hijacker.md>), [gaming](<https://devfeed.tech/tags/gaming.md>), [malware](<https://devfeed.tech/tags/malware.md>), [pay-per-install](<https://devfeed.tech/tags/pay-per-install.md>), [payload](<https://devfeed.tech/tags/payload.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>), [youtube](<https://devfeed.tech/tags/youtube.md>)

### AI overview

An investigation of the CL-CRI-1171 cybercrime campaign describes how YouTube gaming lures and SEO poisoning delivered malware through a custom loader. It covers Docro Hijacker, ARKTunnel, and the Insomnia remote access Trojan.

### Source excerpt

An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure appeared first on Unit 42.

## Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

DevFeed: [Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](<https://devfeed.tech/articles/spring-ring-an-inside-look-at-voice-phishing-campaigns-in-microsoft-teams-7760.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/>)

Author: Noam Sala

Published: 2026-08-31T10:00:36Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [remote access software](<https://devfeed.tech/topics/remote-access-software.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [Cloaked Ursa](<https://devfeed.tech/topics/cloaked-ursa.md>), [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [cloaked-ursa](<https://devfeed.tech/tags/cloaked-ursa.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [microsoft-teams](<https://devfeed.tech/tags/microsoft-teams.md>), [payload](<https://devfeed.tech/tags/payload.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [spoof](<https://devfeed.tech/tags/spoof.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>), [vishing](<https://devfeed.tech/tags/vishing.md>), [voice](<https://devfeed.tech/tags/voice.md>)

### AI overview

Spring Ring is a coordinated social engineering campaign that used external Microsoft Teams accounts and voice phishing to impersonate IT help desk staff. The operation targeted more than 150 employees across at least 10 companies and attempted to deliver remote monitoring and management tools or custom malware. A more advanced variant escalated to an NTLM relay attack against an organization's domain controller.

### Source excerpt

Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on Unit 42.

## AsyncAPI supply chain compromise: npm packages backdoored via GitHub Actions "pwn request" (July 2026)

DevFeed: [AsyncAPI supply chain compromise: npm packages backdoored via GitHub Actions "pwn request" (July 2026)](<https://devfeed.tech/articles/asyncapi-supply-chain-compromise-npm-packages-backdoored-via-github-actions-pwn-request-july-2026-12890.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/asyncapi-supply-chain-compromise-npm-packages-backdoored-via-github-actions>)

Published: 2026-07-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [AsyncAPI Specification](<https://devfeed.tech/topics/asyncapi.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Remote Access Trojan](<https://devfeed.tech/topics/remote-access-trojan.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>)

Tags: [asyncapi-supply-chain-attack](<https://devfeed.tech/tags/asyncapi-supply-chain-attack.md>), [chainguard-asyncapi](<https://devfeed.tech/tags/chainguard-asyncapi.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [ci](<https://devfeed.tech/tags/ci.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [github-actions-pwn-request](<https://devfeed.tech/tags/github-actions-pwn-request.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [malware](<https://devfeed.tech/tags/malware.md>), [miasma](<https://devfeed.tech/tags/miasma.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [personal-access-token](<https://devfeed.tech/tags/personal-access-token.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [tokens](<https://devfeed.tech/tags/tokens.md>)

### AI overview

The article analyzes a July 14, 2026 supply-chain compromise in which an attacker stole a privileged GitHub personal access token through a misconfigured GitHub Actions workflow and used it to publish five backdoored versions across four AsyncAPI npm packages. The malware activates when a library is loaded by a build or CI job and steals browser passwords, SSH keys, npm and GitHub tokens, cloud credentials, and cryptocurrency wallets while maintaining command-and-control access. It also explains why Chainguard customers were protected and recommends treating affected environments as compromised and rotating credentials.

### Source excerpt

A supply chain attack compromised AsyncAPI npm packages via GitHub Actions. See how Chainguard blocked the malicious releases by design.

## The full Snyk AI Security Platform, free for open source maintainers

DevFeed: [The full Snyk AI Security Platform, free for open source maintainers](<https://devfeed.tech/articles/the-full-snyk-ai-security-platform-free-for-open-source-maintainers-8077.md>)

Original publisher: [Read original article](<https://snyk.io/blog/secure-developer-program/>)

Author: Brendan Hann

Published: 2026-06-18T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Frontier Model](<https://devfeed.tech/topics/frontier-model.md>), [Remote Access Trojan](<https://devfeed.tech/topics/remote-access-trojan.md>), [AI Infrastructure](<https://devfeed.tech/topics/ai-infrastructure.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-infrastructure](<https://devfeed.tech/tags/ai-infrastructure.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [article](<https://devfeed.tech/tags/article.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [bugs](<https://devfeed.tech/tags/bugs.md>), [developer](<https://devfeed.tech/tags/developer.md>), [enablement](<https://devfeed.tech/tags/enablement.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [frontier-model](<https://devfeed.tech/tags/frontier-model.md>), [interest](<https://devfeed.tech/tags/interest.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [snyk-iac](<https://devfeed.tech/tags/snyk-iac.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [snyk-team](<https://devfeed.tech/tags/snyk-team.md>), [software](<https://devfeed.tech/tags/software.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

Snyk's Secure Developer Program gives qualifying open source projects free access to the Snyk AI Security Platform. It is designed to help maintainers prioritize real vulnerability reports and produce validated, merge-ready fixes through the Snyk Remediation Agent.

### Source excerpt

Open source maintainers are drowning in real vulnerability reports and need help prioritizing, fixing, and shipping remediation faster. Snyk's Secure Developer Program gives qualifying projects free access to the Snyk AI Security Platform.

## @mastra npm scope takeover: 143 packages backdoored via compromised contributor account

DevFeed: [@mastra npm scope takeover: 143 packages backdoored via compromised contributor account](<https://devfeed.tech/articles/mastra-npm-scope-takeover-143-packages-backdoored-via-compromised-contributor-account-13149.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/mastra-npm-scope-takeover-143-packages-backdoored-via-compromised-contributor-account>)

Published: 2026-06-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Remote Access Trojan](<https://devfeed.tech/topics/remote-access-trojan.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [C2](<https://devfeed.tech/topics/c2.md>)

Tags: [c2](<https://devfeed.tech/tags/c2.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-packages](<https://devfeed.tech/tags/chainguard-packages.md>), [command-and-control](<https://devfeed.tech/tags/command-and-control.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mastra](<https://devfeed.tech/tags/mastra.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-takeover](<https://devfeed.tech/tags/npm-takeover.md>), [packages](<https://devfeed.tech/tags/packages.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [remote-access](<https://devfeed.tech/tags/remote-access.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [secure-packages](<https://devfeed.tech/tags/secure-packages.md>), [software-packages](<https://devfeed.tech/tags/software-packages.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [tls](<https://devfeed.tech/tags/tls.md>)

### AI overview

The article reports that an attacker used a compromised former contributor account to republish all 143 packages in the @mastra npm scope on June 17, 2026. The malicious versions could disable TLS verification, download a cryptocurrency wallet stealer and remote access trojan, and establish command-and-control access. It recommends auditing dependency trees and lockfiles and rotating credentials on affected hosts.

### Source excerpt

A supply chain attack compromised all 143 @mastra packages. Chainguard customers stayed protected through malware blocking and source-built libraries.

## A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope

DevFeed: [A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope](<https://devfeed.tech/articles/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope-7788.md>)

Original publisher: [Read original article](<https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/>)

Author: Liran Tal; Marian Corneci

Published: 2026-06-16T21:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cross-platform](<https://devfeed.tech/tags/cross-platform.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [incident](<https://devfeed.tech/tags/incident.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [payload](<https://devfeed.tech/tags/payload.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [scm](<https://devfeed.tech/tags/scm.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [tech](<https://devfeed.tech/tags/tech.md>), [tls](<https://devfeed.tech/tags/tls.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

A dormant former-contributor npm account was compromised and used to republish the Mastra package scope with a malicious dependency that installs cryptocurrency-stealing malware and a persistent remote-access trojan. The article describes the stale access control that enabled the supply-chain incident and advises treating affected installations as credential and wallet exposure events.

### Source excerpt

A dormant contributor account was used to republish the entire @mastra npm scope, each injected with a single dependency, easy-day-js, that drops a cross-platform cryptocurrency stealer. Here is how the attack worked, how to check exposure, and how to remediate.

## BTMOB: A stealthy RAT burrowing deep into Android devices

DevFeed: [BTMOB: A stealthy RAT burrowing deep into Android devices](<https://devfeed.tech/articles/btmob-a-stealthy-rat-burrowing-deep-into-android-devices-8390.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/>)

Author: Daniel Cunha Barbosa

Published: 2026-05-26T08:50:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Remote Access Trojan](<https://devfeed.tech/topics/remote-access-trojan.md>), [Android](<https://devfeed.tech/topics/android.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [APK](<https://devfeed.tech/topics/apk.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [Accessibility](<https://devfeed.tech/topics/accessibility.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [code](<https://devfeed.tech/tags/code.md>), [malware](<https://devfeed.tech/tags/malware.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [tool](<https://devfeed.tech/tags/tool.md>)

### AI overview

BTMOB is an Android remote access trojan that spreads through phishing websites, fake app stores, and malicious APKs. It can exfiltrate sensitive data, capture screenshots, record device activity, and enable remote control. Its APK builder and malware-as-a-service model make customized campaigns easier to launch.

### Source excerpt

The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise

## Malicious axios versions published to npm: Chainguard customers protected

DevFeed: [Malicious axios versions published to npm: Chainguard customers protected](<https://devfeed.tech/articles/malicious-axios-versions-published-to-npm-chainguard-customers-protected-13145.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/malicious-axios-versions-published-to-npm-chainguard-customers-protected>)

Published: 2026-03-31T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [axios](<https://devfeed.tech/topics/axios.md>), [npm](<https://devfeed.tech/topics/npm.md>), [Remote Access Trojan](<https://devfeed.tech/topics/remote-access-trojan.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [payload](<https://devfeed.tech/topics/payload.md>), [Single-page application (SPA)](<https://devfeed.tech/topics/spa.md>), [Filesystems](<https://devfeed.tech/topics/filesystems.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [Script](<https://devfeed.tech/topics/script.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [macOS](<https://devfeed.tech/topics/macos.md>)

Tags: [axios](<https://devfeed.tech/tags/axios.md>), [axios-attack](<https://devfeed.tech/tags/axios-attack.md>), [axios-npm-attack](<https://devfeed.tech/tags/axios-npm-attack.md>), [axios-supply-chain-attack](<https://devfeed.tech/tags/axios-supply-chain-attack.md>), [c2](<https://devfeed.tech/tags/c2.md>), [chainguard-actions](<https://devfeed.tech/tags/chainguard-actions.md>), [chainguard-axios](<https://devfeed.tech/tags/chainguard-axios.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-npm-libraries](<https://devfeed.tech/tags/chainguard-npm-libraries.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [files](<https://devfeed.tech/tags/files.md>), [http](<https://devfeed.tech/tags/http.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [linux](<https://devfeed.tech/tags/linux.md>), [macos](<https://devfeed.tech/tags/macos.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [payload](<https://devfeed.tech/tags/payload.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [script](<https://devfeed.tech/tags/script.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

The article reports that two malicious axios versions were published to npm with a hidden dependency that deployed a cross-platform remote access trojan on macOS, Windows, and Linux. It explains the compromised maintainer account, post-install execution, command-and-control communication, payload delivery, and recommended auditing and remediation steps. Chainguard customers were protected by package-blocking and source-verification controls.

### Source excerpt

Malicious axios versions on npm delivered a RAT via a hidden dependency. Chainguard customers were protected by blocking unsafe packages and verifying source.

## Compromised axios npm package delivers cross-platform RAT

DevFeed: [Compromised axios npm package delivers cross-platform RAT](<https://devfeed.tech/articles/compromised-axios-npm-package-delivers-cross-platform-rat-8274.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/axios-npm-supply-chain-compromise/>)

Author: Christophe Tafani-Dereeper

Published: 2026-03-31T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [Remote Access Trojan](<https://devfeed.tech/topics/remote-access-trojan.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [account takeover](<https://devfeed.tech/topics/account-takeover.md>), [payload](<https://devfeed.tech/topics/payload.md>), [npm](<https://devfeed.tech/topics/npm.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [account-takeover](<https://devfeed.tech/tags/account-takeover.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [linux](<https://devfeed.tech/tags/linux.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [payload](<https://devfeed.tech/tags/payload.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

The article analyzes a March 31, 2026 supply-chain compromise in which an attacker hijacked an axios npm maintainer account and published two malicious releases. The releases added a typosquatted dependency that installed a cross-platform remote access trojan, though bugs limited the Windows and Linux payloads. The compromise lasted about three hours before npm removed the packages.

### Source excerpt

An attacker hijacked an axios maintainer's npm account to publish malicious releases that deliver a cross-platform RAT.

## Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT

DevFeed: [Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT](<https://devfeed.tech/articles/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform-rat-7839.md>)

Original publisher: [Read original article](<https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/>)

Author: Liran Tal

Published: 2026-03-30T23:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [StreamRAT](<https://devfeed.tech/topics/streamrat.md>), [cross-platform](<https://devfeed.tech/topics/cross-platform.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [ide](<https://devfeed.tech/topics/ide.md>), [client](<https://devfeed.tech/topics/client.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [c2](<https://devfeed.tech/tags/c2.md>), [ci](<https://devfeed.tech/tags/ci.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [code](<https://devfeed.tech/tags/code.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [github](<https://devfeed.tech/tags/github.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware](<https://devfeed.tech/tags/malware.md>), [obfuscation](<https://devfeed.tech/tags/obfuscation.md>), [payload](<https://devfeed.tech/tags/payload.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [security](<https://devfeed.tech/tags/security.md>), [server](<https://devfeed.tech/tags/server.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

The article analyzes a supply-chain attack in which malicious Axios versions published to npm through a compromised maintainer account introduced a hidden dependency. Installing the affected packages could trigger a postinstall dropper that downloaded a platform-specific remote access trojan, contacted a command-and-control server, and erased evidence after execution.

### Source excerpt

Meta description: Malicious versions of the Axios npm package (1.14.1 and 0.30.4) were published via a compromised maintainer account, injecting a hidden dependency that deploys a cross-platform remote access trojan. Here's what happened, who's affected, and how to check your exposure.