Skip to content

Compromised axios npm package detected in CI workflow runs #1103

Description

@varunsh-coder

StepSecurity's Harden Runner detected that recent CI workflow runs in this repository executed a compromised version of the axios npm package that communicates with a known command-and-control (C2) domain.

What happened

Multiple versions of the axios npm package (v1.14.1 and v0.30.4) were compromised and published to npm. These versions contain a remote access trojan (RAT) that connects to the C2 domain sfrclak.com. For full details, see our blog post: Axios Compromised on NPM: Malicious Versions Drop Remote Access Trojan

Affected workflow runs

Harden Runner detected outbound network connections to the C2 domain sfrclak.com in the following workflow runs of .github/workflows/ci.yaml:

Run ID Timestamp (UTC) StepSecurity Insights
23775131074 2026-03-31T05:26:26Z View Insights
23775155550 2026-03-31T05:26:28Z View Insights
23776574145 2026-03-31T05:28:37Z View Insights

How to verify

For each workflow run linked above, go to the StepSecurity Insights page and search for sfrclak.com in the network events to see where the C2 domain was contacted.

Recommended actions

  • Rotate any credentials — If the affected workflow runs had access to secrets or credentials (API keys, tokens, deployment keys, etc.), rotate them immediately. The RAT may have exfiltrated sensitive data.

How this was detected

StepSecurity Harden Runner monitors network traffic from GitHub Actions workflow runs in real-time.

We are proactively reaching out to affected repositories to help mitigate the impact.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions