A sophisticated supply chain attack recently compromised the popular JavaScript library Axios, affecting two specific versions with over 100 million weekly downloads. The breach originated from a compromised maintainer account, allowing attackers to inject a rogue dependency called PlainCryptoJS that utilizes a post-install script to deploy a Remote Access Trojan (RAT). This "RATDropper" detects the host operating system, fetches a tailored second-stage payload from a command-and-control server, and establishes remote access to steal sensitive credentials like AWS and OpenAI API keys. The malware maintains a clean profile by deleting its own footprints and modifying package files to bypass detection from tools like npm audit. Affected developers must identify the malicious versions, check for the RAT file, and immediately rotate all environment tokens and keys to mitigate the risk of total system compromise.
Sign in to continue reading, translating and more.
Open full episode in Podwise
