The DNS Anatomy of the Axios Supply Chain Attack

GTIG uncovered1 a UN1069 attack targeting the widely used NPM package axios at the end of March 2026, with detailed analysis released shortly after. Elastic Security Labs disclosed2 additional IoCs, while GitHub listed3 another set of IoCs associated with the campaign.

After deduplication, domain extraction from subdomains, and filtering of legitimate infrastructure, we analyzed 22 IoCs, including five subdomains, seven domains, and 10 IP addresses. Using our DNS intelligence capabilities, we uncovered the following findings:

  • 16 unique client IP addresses that communicated with two of the domain IoCs
  • Two domain IoCs appeared in two typosquatting groups with 5–12 members each
  • One domain IoC likely registered with malicious intent 651 days before being confirmed as malicious
  • 32 distinct IP addresses potentially owned by victims that communicated with seven of the IP IoCs
  • 676 email-connected domains
  • Two additional IP addresses, both confirmed as malicious
  • 58 IP-connected domains, four of which were confirmed as malicious
  • 1,034 string-connected domains, one of which was confirmed as malicious

Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

  • [1] https://cloud.google.com/blog/topics/threat-intelligence/north-korea-threat-actor-targets-axios-npm-package
  • [2] https://www.elastic.co/security-labs/axios-one-rat-to-rule-them-all
  • [3] https://gist.github.com/N3mes1s/0c0fc7a0c23cdb5e1c8f66b208053ed6
Try our WhoisXML API for free
Get started