Junglewise Threat Intelligence

axioss malicious package

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The axioss npm package contained embedded malicious code designed to exfiltrate system information (OS type, hostname) to a remote server. Applications that installed this package could have their infrastructure details harvested by attackers, potentially enabling further targeted attacks on the compromised environment.

Technical details

This is a supply-chain attack involving intentionally malicious code injected into the axioss npm package (all versions from 0.0.0 onwards). The malware performs reconnaissance by collecting and transmitting OS and hostname information to an attacker-controlled server. No authentication or user interaction is required—the malicious code executes automatically upon package installation. The attack vector is network-based via package distribution. The primary mitigation is immediate removal of the affected package from all environments; there are no legitimate patches as the package itself is compromised.

Affected products

  • npm axioss all versions from 0.0.0

Timeline

  • 2020-09-03: disclosed

References