VDB

GCVE-110-OSM-2026-1162

GCVE-110-OSM-2026-1162
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published March 31, 2026
Legitimate axios npm package compromised via hijacked maintainer account. Malicious versions 1.14.1 and 0.30.4 were published by an attacker who changed the maintainer email to ifstap@proton.me. The compromised package contacts a C2 server and drops platform-specific RAT payloads (macOS, Windows, Linux). After execution, the malware deletes itself and replaces its own package.json with a clean version to evade forensic detection. === PAYLOAD: Multi-platform RAT Dropper === C2 URL: http://sfrclak.com:8000/6202033 C2 IP: 142.11.206.73 Behavior: Contacts C2 server and delivers platform-specific second-stage payloads: - macOS: /Library/Caches/com.apple.act.mond - Windows: %PROGRAMDATA%\wt.exe - Linux: /tmp/ld.py After execution, the malware deletes itself and replaces its own package.json with a clean version to evade forensic detection. Published via npm CLI bypassing normal CI/CD processes.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownaxios

References

vendor

Browse GCVE Records

74,299 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›