if __name__ == '__n34r__' retweetledi

The Axios threat actors are on the move again.
The NPM package mgc (v1.2.1-1.2.4)
Almost the same malware - but the payloads are hosted on GitHub.
C2 is live but not yet weaponized.
Thanks @abh1sek for pointing this out
My blog on the Axios incident
ox.security/blog/axios-com…

English


































