Live Wave Icon New Blog: Mini Shai-Hulud "Miasma" Hits @redhat-cloud-services: 32 Packages at Risk
•
Edit Calendar Icon 1 Jun 2026
SafeDep Logo
Pricing
Discover & Monitor
SCA & SBOM
SCA & SBOM

Scan dependencies, generate SBOMs, enforce policy.

AI Agent Discovery
AI Agent Discovery

See every AI tool and SDK in your org.

AI Agent Monitoring
AI Agent Monitoring

Audit every action your AI agents take.

Protect
Developer Security
Developer Security

Block malicious packages at install-time.

CI/CD Security
CI/CD Security

Block malicious packages in your pipeline.

MCP Server
MCP Server

Block threats inside your AI coding agent.

Agent API
Agent API

Threat intelligence API for custom agents.

Threat Intelligence
Threat Intelligence

Real-time malicious package verdicts.

Govern
Endpoint Protection
Endpoint Protection

Package events & AI inventory in the cloud.

Platform
Platform

Centralized policies, dashboard, compliance.

Vet
Vet

Scan and govern your dependencies across every PR and build.

PMG
PMG

Block malicious packages at install-time, before they enter your codebase.

xbom
xbom

Generate AI-enriched BOMs using real code evidence, not just manifests.

GRYPH
GRYPH

Monitor every AI coding agent action across your projects and workflows.

How it works Blog
Documentation
SDK
API
Threat Intelligence Hub
Login Start for Free GitHub 1.5k Discord
packages npm
malware npm

axios

discovered 2026-03-31

axios is identified in the SafeDep analysis "axios Compromised: npm Supply Chain Attack via Dependency Injection". axios 1.14.1 was published to npm via a compromised maintainer account, injecting a trojanized dependency that executes a multi-platform reverse shell on install. No source code changes in axios itself, just a new entry in package.json.

Threat types

rat persistence

Malicious versions

  • 1.8.2

Campaigns

  • No Specific Campaignattributed-to

Indicators

  • domain sfrclak.comcommunicates-with
  • ipv4 142.11.206.73communicates-with
  • sha256 5bb67e88846096f1f8d42a0f0350c9c46260591567612ff9af46f98d1b7571cdindicates
  • sha256 59336a964f110c25c112bcc5adca7090296b54ab33fa95c0744b94f8a0d80c0findicates
  • sha256 fcb81618bb15edfdedfb638b4c08a2af9cac9ecfa551af135a8402bf980375cfindicates
  • sha256 e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09indicates
  • email npm-oidc-no-reply@github.comexfiltrates-to
  • email ifstap@proton.meexfiltrates-to
  • email jasonsaayman@gmail.comexfiltrates-to
  • email nrwise@proton.meexfiltrates-to

Techniques

  • ttp T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Toolsuses
  • ttp T1059.007 Command and Scripting Interpreter: JavaScriptuses
  • ttp T1528 Steal Application Access Tokenuses
  • ttp T1105 Ingress Tool Transferuses
  • ttp T1071.001 Application Layer Protocol: Web Protocolsuses
  • ttp T1102 Web Serviceuses
  • ttp T1546 Event Triggered Executionuses
Read the full analysis →
SafeDep Logo
SafeDep
Terms · Privacy Policy
SOC 2 Type II Certified
ISO 27001:2013 Certified
SOC 2 Type II Certified
ISO 27001:2013 Certified
SOC 2 Type II Certified
ISO 27001:2013 Certified
Product
  • Features
  • Pricing
  • How it works
Solutions
  • AI Agent Discovery
  • AI Agent Monitoring
  • Threat Intel for Agents
  • Threat Intel for SecOps
  • MCP Server
  • Endpoint Protection
  • Threat Intel Data Hub
  • Developer API
  • Partners
Support
  • Docs
  • Community Forum
  • FAQ
  • Professional Services
  • Status
Company
  • About
  • Blog
  • Contact
  • Careers
  • GitHub
© 2026 SafeDep, Inc. All rights reserved