Junglewise Threat Intelligence

axois malicious package with remote command execution

Severity: low · CVSS 3.1 · Published 2020-09-01

Vendors: npm.

Executive brief

The npm package "axois" is a typosquatting attack delivering malware to developers who mistype the popular axios HTTP library name. When installed and executed, the package connects to a command and control server to download and run arbitrary code, giving attackers complete control over the developer's machine and any systems or credentials accessible from it.

Technical details

This package is intentional malware (CWE-506: Embedded Malicious Code) published to the npm registry as a typosquatting variant of the legitimate "axios" library. The malware executes immediately upon package installation or first use, establishing an outbound connection to a remote command and control server to fetch and execute arbitrary commands with the privileges of the user running Node.js. No authentication is required—installation alone via `npm install axois` (instead of the correct `axios`) triggers the attack. An attacker gains remote code execution on the developer's machine, with access to all environment variables, source code, API keys, and credentials present on that system.

Affected products

  • npm axois all

Timeline

  • 2020-09-01: disclosed: Vulnerability published to OSV database

References