Weekly review

ThreatNoir Morning Brief — April 2

2026-04-02Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — April 2, 2026

The threat landscape continues to evolve with significant developments across supply chain security, zero-day exploits, and credential-based attacks. Today's review covers critical incidents affecting widely deployed software libraries and enterprise communication platforms, alongside emerging malicious services targeting cloud authentication mechanisms.

Mitigating the Axios npm Supply Chain Compromise

On March 31, 2026, the popular HTTP client Axios experienced a significant supply chain attack when two newly published npm packages for version updates (1.14.1 and 0.30.4) were configured to download from command and control infrastructure. Microsoft Threat Intelligence has attributed the attack to Sapphire Sleet, a North Korean state actor. Given that Axios ranks among the most widely used HTTP client libraries in the JavaScript ecosystem, the compromise potentially exposed hundreds to millions of users to malicious code execution. Although the malicious versions have been removed from npm, the incident underscores the vulnerability of open-source dependencies to state-sponsored threats. Source: Mitigating the Axios npm supply chain compromise

Axios npm Package Compromised via Stolen Maintainer Credentials

A threat actor leveraged stolen maintainer credentials to compromise the Axios Node Package Manager package on March 31, 2026, deploying platform-specific ZshBucket variants across affected systems. CrowdStrike Counter Adversary Operations has attributed the attack to an advanced threat actor exploiting legitimate access to the package repository. The incident demonstrates how compromised credentials for high-visibility open-source projects can serve as a vector for widespread malware distribution. Source: 🚨 Breaking: On March 31, 2026, a threat actor used stolen maintainer credentials to compromise t...

Hackers Exploit TrueConf Zero-Day to Push Malicious Software Updates

Attackers have exploited a zero-day vulnerability in TrueConf conference servers to execute arbitrary files on all connected endpoints. The vulnerability, tracked as CVE-2026-3502, allows threat actors to abuse the software update mechanism for malware distribution. Security researchers have identified multiple malicious payloads associated with the campaign, including tools attributed to Amaranth Dragon and the Havoc C2 framework. The exploitation of update mechanisms represents a particularly dangerous attack vector, as legitimate software updates are typically trusted by end users and security controls. Source: Hackers exploit TrueConf zero-day to push malicious software updates

New EvilTokens Service Fuels Microsoft Device Code Phishing Attacks

A new malicious service called EvilTokens has emerged to facilitate device code phishing attacks targeting Microsoft accounts. The service integrates advanced capabilities that enable attackers to hijack Microsoft credentials and conduct sophisticated business email compromise operations. By automating device code phishing workflows, EvilTokens lowers the technical barrier for threat actors seeking to gain persistent access to enterprise environments. The service represents a concerning evolution in credential theft techniques, particularly given the widespread adoption of Microsoft cloud services across organizations. Source: New EvilTokens service fuels Microsoft device code phishing attacks

Organizations should prioritize patching the TrueConf zero-day, auditing npm package dependencies for malicious versions, and implementing enhanced monitoring for device code authentication flows. The convergence of supply chain attacks, zero-day exploits, and credential-focused threats reflects an increasingly sophisticated threat environment requiring layered defensive strategies.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Mitigating the Axios npm supply chain compromise
Malware3
  • com.apple.act.mond
    macOS-specific RAT payload delivered via second-stage loader
  • plain-crypto-js@4.2.1
    Malicious npm package injected as fake dependency into Axios to trigger install-time code execution
  • Sapphire Sleet
    North Korean state-sponsored threat actor attributed to the Axios supply chain compromise
IP Address1
  • 142.11.206.73
    C2 server IP (port 8000) hosted on Hostwinds VPS, tied to Sapphire Sleet infrastructure
Domain1
  • sfrclak.com
    Sapphire Sleet C2 domain used to deliver second-stage RAT payload
URL1
  • hxxp://sfrclak[.]com:8000/6202033
    C2 endpoint for second-stage payload delivery across all platforms
Hackers exploit TrueConf zero-day to push malicious software updates
CVE1
  • Zero-day vulnerability in TrueConf versions 8.1.0–8.5.2 affecting update mechanism integrity
Malware7
  • iscsiexe.dll
    Suspicious artifact present in TrueChaos compromised systems
  • Havoc C2
    Open-source command-and-control framework deployed post-compromise; network traffic identified Havoc infrastructure
  • TrueChaos
    Chinese-nexus APT campaign exploiting CVE-2026-3502 against Southeast Asian government entities since early 2026
  • poweriso.exe
    Suspicious artifact and indicator of compromise in TrueChaos infections
  • 7z-x64.dll
    Suspicious artifact and indicator of compromise in TrueChaos infections
  • iscicpl.exe
    Used for UAC bypass and privilege escalation in TrueChaos attack chain
  • Amaranth Dragon
    Chinese threat cluster previously using Havoc C2 with similar targeting scope