[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.jp/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/ja/)  
Menu

* [セキュリティ コンサルティング](https://www.paloaltonetworks.com/unit42)
* [**現在、攻撃を受けていますか?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  Japanese
* [English](https://unit42.paloaltonetworks.com/axios-supply-chain-attack/)
* [Spanish (LATAM)](https://unit42.paloaltonetworks.com/es-la/axios-supply-chain-attack/)
* [French](https://unit42.paloaltonetworks.com/fr/axios-supply-chain-attack/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/)
* [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research")
* [主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/ "主なサイバー脅威")
* [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/ "マルウェア")  
  [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)

# 脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 3 分で読めます  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/ja/product-category/advanced-dns-security-ja/ "Advanced DNS Security")[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/ja/product-category/advanced-threat-prevention-ja/ "Advanced Threat Prevention")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/ja/product-category/advanced-url-filtering-ja/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/ja/product-category/advanced-wildfire-ja/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/ja/product-category/cloud-delivered-security-services-ja/ "Cloud-Delivered Security Services")[![Cortex icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex](https://unit42.paloaltonetworks.com/ja/product-category/cortex-ja/ "Cortex")[Cortex Cloud](https://unit42.paloaltonetworks.com/ja/product-category/cortex-cloud-ja/ "Cortex Cloud")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/ja/product-category/cortex-xdr-ja/ "Cortex XDR")[![Cortex XSIAM icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XSIAM](https://unit42.paloaltonetworks.com/ja/product-category/cortex-xsiam-ja/ "Cortex XSIAM")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/ja/product-category/unit-42-incident-response-ja/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  著者:
  
  * [Unit 42](https://unit42.paloaltonetworks.com/ja/author/unit42/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  公開日:2026年4月1日

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  カテゴリー
  
  * [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)
  * [主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  タグ:
  
  * [API attacks](https://unit42.paloaltonetworks.com/ja/tag/api-attacks-ja/)
  * [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/)
  * [Powershell](https://unit42.paloaltonetworks.com/ja/tag/powershell-ja/)
  * [Supply chain](https://unit42.paloaltonetworks.com/ja/tag/supply-chain-ja/)
  * [Trojan](https://unit42.paloaltonetworks.com/ja/tag/trojan-ja/)
  * [VBScript](https://unit42.paloaltonetworks.com/ja/tag/vbscript-ja/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/?pdf=download&lg=ja&_wpnonce=7faf0ddf08 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/?pdf=print&lg=ja&_wpnonce=7faf0ddf08 "Click here to print")

共有![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=脅威概要:Axiosサプライ%20チェーン攻撃で広範に及ぶ影響&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Faxios-supply-chain-attack%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Faxios-supply-chain-attack%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Faxios-supply-chain-attack%2F&title=脅威概要:Axiosサプライ%20チェーン攻撃で広範に及ぶ影響 "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Faxios-supply-chain-attack%2F&text=脅威概要:Axiosサプライ%20チェーン攻撃で広範に及ぶ影響 "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Faxios-supply-chain-attack%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=脅威概要:Axiosサプライ%20チェーン攻撃で広範に及ぶ影響%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Faxios-supply-chain-attack%2F "Share in Mastodon")

## エグゼクティブ サマリー

Unit 42のリサーチャーは、AxiosのJavaScriptライブラリを標的とした重大なサプライ チェーン攻撃による広範囲に及ぶ影響を観察しました。この攻撃は、Axiosメンテナーのnpmアカウントが乗っ取られ、悪意のあるアップデート(バージョンv1.14.1とv0.30.4)が公開された後に発生しました。

これらの侵害されたバージョンでは、plain-crypto-jsと呼ばれる隠れた依存関係が導入されました。この依存性は、Windows、macOS、およびLinuxの各システムに影響を与えることのできるクロスプラットフォームのリモートアクセス型トロイの木馬(RAT)です。このマルウェアは、偵察を行って、持続性を確立する設計になっており、検出回避のための自己破壊機能が追加されています。

Axiosは、JavaScript用のプロミス ベースのHTTPクライアント ライブラリとして人気があり、ブラウザやNode.jsでAPIリクエストを行うために使用されています。JSONデータの自動変換、リクエスト/レスポンスの傍受、リクエスト キャンセルなどの機能を備えており、フロントエンド アプリとバックエンド サービスを接続するための標準的なツールになっています。

攻撃者が使用したマルウェアの分析結果は、[以前報告された](https://cloud.google.com/blog/topics/threat-intelligence/unc1069-targets-cryptocurrency-ai-social-engineering)朝鮮民主主義人民共和国(DPRK)が関与していることが以前報告されたオペレーションと重複しています。

このキャンペーンは、アメリカ、ヨーロッパ、中東、南アジア、オーストラリアの以下のセクターに影響を与えました:

* ビジネス サービス
* カスタマー サービス
* 金融サービス
* ハイテク
* 高等教育
* 保険
* メディア エンターテインメント
* 医療機器
* 専門的サービスや法務サービス
* 小売サービス

この記事では、多くの[攻撃緩和策](#post-179518-_heading=h.mub7pjizsyhy)を推奨しています。

パロアルトネットワークスのお客様は、以下の製品を通じて、本書で取り上げるツールに対する確実な保護を構築いただけます:

* [Advanced URL Filtering](https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-new-features/url-filtering-features/advanced-url-filtering)および[Advanced DNS Security](https://docs.paloaltonetworks.com/dns-security)
* [Advanced Threat Prevention](https://docs.paloaltonetworks.com/advanced-threat-prevention/administration)
* [Advanced WildFire](https://docs.paloaltonetworks.com/wildfire)
* [Cortex AgentiX](https://www.paloaltonetworks.com/cortex/agentix)
* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)
* [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR)および[XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM)

[Unit 42インシデント レスポンス](https://start.paloaltonetworks.com/contact-unit42.html)チームは、お客様のリスクを低減するために、侵害の際の支援や、プロアクティブな評価の提供にも取り組んでいます。

| **議論された脆弱性** | [**サプライ チェーン**](https://unit42.paloaltonetworks.com/ja/tag/supply-chain-ja/)、[**ハイ プロファイル スレット**](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) |
|--------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------|

## Axiosサプライ チェーン攻撃の詳細

攻撃者によって、2つの侵害されたバージョンのAxios(v1.14.1とv0.30.4)が公開されましたが、Axiosのソースコードには一切手は加えられていません。代わりに、plain-crypto-js@4.2.1が、package.jsonファイルに実行時依存関係として注入されました。

### ポストインストール ドロッパー

侵害されたAxiosのバージョンでは、開発者がnpm install axiosを実行すると、npmによって依存関係ツリーが自動的に解決され、plain-crypto-jsがインストールされます。これで、npmのポストインストール ライフサイクル フックにトリガーがかかり、バックグラウンドでsetup.jsという強度に難読化されたNode.jsドロッパー スクリプトが実行されます。

オペレーションを難読化するために、setup.jsは文字列の反転、Base64デコード、OrDeR\_7077キーを使ったXORサイファーを含む2層のエンコーディングスキームを使用します。

### プラットフォーム固有のペイロードのフェッチ

ドロッパーはオペレーティング システムに問い合わせ、sfrclak\[.\]com:8000にあるコマンド\&コントロール(C2)サーバーにHTTP POSTリクエストを送信します。このアウトバウンド トラフィックを、無害なnpmレジストリ リクエストのように見せるために、ドロッパーはプラットフォーム固有のパスを付加します:

* macOS用packages.npm\[.\]org/product0
* Windows用packages.npm\[.\]org/product1
* Linux用packages.npm\[.\]org/product2

図1は、この第1段階のダウンロードのコマンドを示しています。
![各オペレーティング システム(macOS、Windows、Linux)のコマンドのコード スニペット。](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/word-image-620919-179518-1.png) 図1.プラットフォームごとの第1段階のダウンロード。

### RATの実行

C2サーバーは、被害者のオペレーティング システムに応じて異なるペイロードを配信します:

* **macOS** :ドロッパーは、C++でコンパイルされたMach-OバイナリをAppleScriptでダウンロードし、それを/Library/Caches/com.apple.act.mondに保存して実行可能にし、/bin/zsh経由でサイレントに起動します。
* **Windows** :ドロッパーは Windows PowerShell のバイナリを検索し、%PROGRAMDATA%\\wt.exe にコピーします。次に、VBScript を使用して二次的な PowerShell RAT スクリプトを取得して実行し、続いてそのスクリプトが wt.exe によって実行されます。また、レジストリの Run キーを介して永続性を確立します。
* **Linux** :ドロッパーは、Node.jsのexecSyncコマンドでPythonのRATスクリプトを/tmp/ld.pyにダウンロードし、nohupコマンドでそれをバックグラウンドで実行します。

### 統合型RATアーキテクチャ

3つの異なる言語(C++、PowerShell、Python)で書かれていますが、3つのペイロードはすべて同じRATフレームワークの実装として機能します。

これらはすべて同じC2プロトコルを使用し、HTTP POSTリクエストに対してBase64エンコードされたJSONデータを送信し、60秒ごとにサーバーにビーコンを送ります。C2サーバーは攻撃者から同じ4つのコマンドを受け取ります:

* kill(セルフターミネート)
* runscript(シェルを実行/スクリプト コマンド)
* peinject(バイナリペイロードをドロップして実行)
* rundir(ディレクトリ列挙)

RATバリアントはすべて、Windows XP上のInternet Explorer 8になりすます、ハードコードされた非常に時代錯誤なユーザーエージェント文字列を使用します: mozilla/4.0 (compatible; msie 8.0; windows nt 5.1; trident/4.0.

### WAVESHAPERとのオーバーラップ

ペイロードの初期分析では、[WAVESHAPER](https://cloud.google.com/blog/topics/threat-intelligence/unc1069-targets-cryptocurrency-ai-social-engineering)との重大な[オーバーラップ](https://www.elastic.co/security-labs/axios-one-rat-to-rule-them-all)が確認されています。WAVESHAPERは、コマンドライン引数で指定されたHTTPまたはHTTPSのいずれかを使用し、curlライブラリでC2サーバーと通信するC++バックドアです。

C2サーバーのアドレスもコマンドライン パラメーターで提供されるため、バックドアでは、敵対者のインフラから任意のペイロードをダウンロードして実行することができます。

WAVESHAPERは、親セッションから切り離されたバックグラウンドで実行される子プロセスに自分自身をフォークして、デーモンとしても実行されます。WAVESHAPERは、HTTP POSTリクエストでC2サーバーに送信される返されたシステム情報を収集します。

### **フォレンジック クリーンアップ**

インストールから侵害までの全プロセスにかかる時間はおよそ15秒。ペイロードの起動に成功すると、Node.jsドロッパーは攻撃的なアンチフォレンジック クリーンアップを実行します。Node.jsドロッパーはsetup.jsファイルを削除し、postinstallフックを削除し、改ざんされたpackage.jsonをpackage.mdという名前のクリーンなおとりファイルに置き換えます。これにより、開発者がインストール後にnode\_modulesフォルダを検査しても、悪意のあるコードの明白な兆候は見つかりません。

## Unit 42マネージド脅威ハンティング用クエリ

Unit 42のマネージド スレット ハンティング チームは、Cortex XDRと以下のXQLクエリで、顧客全体でこの状況を悪用しようとする試みを追跡し続けています。Cortex XDRの顧客は、これらのXQLクエリで、悪用の兆候を検索することもできます。  
// Title: Compromised Axios npm package version (1.14.1 and 0.30.4) C2 on Command Line // Description: First stage of activity once a compromised endpoint runs the affected axios package is for the dropper scripts to call out to their C2 domain sfrclak\[.\]com // MITRE ATT\&CK TTP ID: T1105 config case\_sensitive = false | dataset = xdr\_data | fields \_time, event\_type, event\_sub\_type, event\_id, agent\_hostname, agent\_id, action\_process\_image\_command\_line, actor\_process\_command\_line | filter event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START and action\_process\_image\_command\_line ~= "(?:\\bsfrclak\\.com\\b)" | comp values(action\_process\_image\_command\_line) as action\_process\_image\_command\_line, values(actor\_process\_command\_line) as actor\_process\_command\_line by \_time, agent\_hostname, agent\_id

|-------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 | // Title: Compromised Axios npm package version (1.14.1 and 0.30.4) C2 on Command Line // Description: First stage of activity once a compromised endpoint runs the affected axios package is for the dropper scripts to call out to their C2 domain sfrclak\[.\]com // MITRE ATT\&CK TTP ID: T1105 config case\_sensitive = false | dataset = xdr\_data | fields \_time, event\_type, event\_sub\_type, event\_id, agent\_hostname, agent\_id, action\_process\_image\_command\_line, actor\_process\_command\_line | filter event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START and action\_process\_image\_command\_line ~= "(?:\\bsfrclak\\.com\\b)" | comp values(action\_process\_image\_command\_line) as action\_process\_image\_command\_line, values(actor\_process\_command\_line) as actor\_process\_command\_line by \_time, agent\_hostname, agent\_id |

// Title: Compromised Axios npm package version (1.14.1 and 0.30.4) Malicious plain-crypto-js package directory // Description: The malicious package is actually plain-crypto-js, this looks for directory creation events for that package name within a node\_modules folder // MITRE ATT\&CK TTP ID: T1204.005 config case\_sensitive = false | dataset = xdr\_data | fields \_time, event\_type, event\_sub\_type, event\_id, agent\_hostname, agent\_id, action\_file\_path, actor\_process\_command\_line | filter event\_type = ENUM.FILE and event\_sub\_type in (ENUM.FILE\_DIR\_CREATE, ENUM.FILE\_DIR\_WRITE, ENUM.FILE\_DIR\_RENAME) and lowercase(action\_file\_path) ~= "(?:\\bnode\_modules\[\\\\\\/\]plain-crypto-js\\b)" | comp values(action\_file\_path) as action\_file\_path, values(actor\_process\_command\_line) as actor\_process\_command\_line by \_time, agent\_hostname, agent\_id

|-------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 | // Title: Compromised Axios npm package version (1.14.1 and 0.30.4) Malicious plain-crypto-js package directory // Description: The malicious package is actually plain-crypto-js, this looks for directory creation events for that package name within a node\_modules folder // MITRE ATT\&CK TTP ID: T1204.005 config case\_sensitive = false | dataset = xdr\_data | fields \_time, event\_type, event\_sub\_type, event\_id, agent\_hostname, agent\_id, action\_file\_path, actor\_process\_command\_line | filter event\_type = ENUM.FILE and event\_sub\_type in (ENUM.FILE\_DIR\_CREATE, ENUM.FILE\_DIR\_WRITE, ENUM.FILE\_DIR\_RENAME) and lowercase(action\_file\_path) ~= "(?:\\bnode\_modules\[\\\\\\/\]plain-crypto-js\\b)" | comp values(action\_file\_path) as action\_file\_path, values(actor\_process\_command\_line) as actor\_process\_command\_line by \_time, agent\_hostname, agent\_id |

// Title: Compromised Axios npm package version (1.14.1 and 0.30.4) File Indicators // Description: Upon installation of the compromised axios package via npm, the postinstall script deploys dropper scripts to download and install a remote access trojan on Mac, Linux, or Windows endpoints. // MITRE ATT\&CK TTP ID: T1105 \& T1219 config case\_sensitive = false | dataset = xdr\_data | fields \_time, event\_type, event\_sub\_type, event\_id, agent\_hostname, agent\_id, action\_file\_path, actor\_process\_command\_line | filter event\_type = ENUM.FILE and event\_sub\_type in (FILE\_CREATE\_NEW, FILE\_WRITE, FILE\_RENAME) and lowercase(action\_file\_path) ~= "(?:library\\/caches\\/com\\.apple\\.act\\.mond|\\/tmp\\/ld\\.py|c:\\\\programdata\\\\wt\\.exe|appdata\\\\local\\\\temp\\\\6202033\\.(?:ps1|vbs)|c:\\\\programdata\\\\system\\.bat)" | comp values(action\_file\_path) as action\_file\_path, values(actor\_process\_command\_line) as actor\_process\_command\_line by \_time, agent\_hostname, agent\_id

|-------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 | // Title: Compromised Axios npm package version (1.14.1 and 0.30.4) File Indicators // Description: Upon installation of the compromised axios package via npm, the postinstall script deploys dropper scripts to download and install a remote access trojan on Mac, Linux, or Windows endpoints. // MITRE ATT\&CK TTP ID: T1105 \& T1219 config case\_sensitive = false | dataset = xdr\_data | fields \_time, event\_type, event\_sub\_type, event\_id, agent\_hostname, agent\_id, action\_file\_path, actor\_process\_command\_line | filter event\_type = ENUM.FILE and event\_sub\_type in (FILE\_CREATE\_NEW, FILE\_WRITE, FILE\_RENAME) and lowercase(action\_file\_path) ~= "(?:library\\/caches\\/com\\.apple\\.act\\.mond|\\/tmp\\/ld\\.py|c:\\\\programdata\\\\wt\\.exe|appdata\\\\local\\\\temp\\\\6202033\\.(?:ps1|vbs)|c:\\\\programdata\\\\system\\.bat)" | comp values(action\_file\_path) as action\_file\_path, values(actor\_process\_command\_line) as actor\_process\_command\_line by \_time, agent\_hostname, agent\_id |

// Title: Compromised Axios npm package version (1.14.1 and 0.30.4) C2 NGFW Traffic // Description: First stage of activity once a compromised endpoint runs the affected axios package is for the dropper scripts to call out to their C2 domain sfrclak\[.\]com // MITRE ATT\&CK TTP ID: T1105 config case\_sensitive = false | dataset = panw\_ngfw\_url\_raw | filter url\_domain ~= "(?:\\bsfrclak\\.com\\b)" | join type = left ( dataset = panw\_ngfw\_traffic\_raw | fields session\_id, source\_ip, dest\_ip, source\_port, dest\_port, action\_source, bytes\_received, bytes\_sent, bytes\_total, packets\_received, packets\_sent, packets\_total, chunks\_received, chunks\_sent, chunks\_total, session\_end\_reason ) as trafficraw trafficraw.session\_id = session\_id and trafficraw.source\_ip = source\_ip and trafficraw.dest\_ip = dest\_ip and trafficraw.source\_port = source\_port and trafficraw.dest\_port = dest\_port | fields \_time, \_reporting\_device\_name, action, action\_source, source\_ip, source\_port, source\_user, source\_location, dest\_ip, dest\_port, dest\_location, http\_method, http\_headers, uri, url\_category, url\_category\_list, url\_domain, app, app\_category, app\_sub\_category, bytes\_received, bytes\_sent, bytes\_total, packets\_received, packets\_sent, packets\_total, chunks\_received, chunks\_sent, chunks\_total, protocol, inbound\_if, outbound\_if, from\_zone, to\_zone, referer, referer\_fqdn, referer\_port, referer\_protocol, referer\_url\_path, rule\_matched, session\_id, session\_end\_reason, severity, sub\_type, technology\_of\_app, tunneled\_app, vsys | sort desc \_time

|-------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 | // Title: Compromised Axios npm package version (1.14.1 and 0.30.4) C2 NGFW Traffic // Description: First stage of activity once a compromised endpoint runs the affected axios package is for the dropper scripts to call out to their C2 domain sfrclak\[.\]com // MITRE ATT\&CK TTP ID: T1105 config case\_sensitive = false | dataset = panw\_ngfw\_url\_raw | filter url\_domain ~= "(?:\\bsfrclak\\.com\\b)" | join type = left ( dataset = panw\_ngfw\_traffic\_raw | fields session\_id, source\_ip, dest\_ip, source\_port, dest\_port, action\_source, bytes\_received, bytes\_sent, bytes\_total, packets\_received, packets\_sent, packets\_total, chunks\_received, chunks\_sent, chunks\_total, session\_end\_reason ) as trafficraw trafficraw.session\_id = session\_id and trafficraw.source\_ip = source\_ip and trafficraw.dest\_ip = dest\_ip and trafficraw.source\_port = source\_port and trafficraw.dest\_port = dest\_port | fields \_time, \_reporting\_device\_name, action, action\_source, source\_ip, source\_port, source\_user, source\_location, dest\_ip, dest\_port, dest\_location, http\_method, http\_headers, uri, url\_category, url\_category\_list, url\_domain, app, app\_category, app\_sub\_category, bytes\_received, bytes\_sent, bytes\_total, packets\_received, packets\_sent, packets\_total, chunks\_received, chunks\_sent, chunks\_total, protocol, inbound\_if, outbound\_if, from\_zone, to\_zone, referer, referer\_fqdn, referer\_port, referer\_protocol, referer\_url\_path, rule\_matched, session\_id, session\_end\_reason, severity, sub\_type, technology\_of\_app, tunneled\_app, vsys | sort desc \_time |

## まとめ

攻撃者は2026年初頭から、npmのサプライ チェーン オペレーションの頻度と規模を拡大しています。継続的インテグレーション/継続的デプロイメント(CI/CD)パイプラインのセキュリティ確保は、どの組織にとっても、この増大する脅威を緩和するための最優先事項になるはずです。

利用できる情報量に基づいて、以下の行動を強く推奨します:

### 即時評価と隔離

* **悪意のあるパッケージを監査する** :プロジェクトとnode\_modulesディレクトリで、侵害されたAxiosバージョン(1.14.1と0.30.4)と注入されたplain-crypto-jsパッケージ(バージョン4.2.0と4.2.1)を検索してください。
* **マルウェアのアーティファクトをチェックする** : Library/Caches/com.apple.act.mond (macOS)、%PROGRAMDATA%wt.exe (Windows)、/tmp/ld.py (Linux)など、プラットフォーム固有の侵害のインジケーターがないかシステムを検査します。
* **影響を受けるシステムを隔離する**:悪意のあるパッケージやRATアーティファクトを発見したら、システムをネットワークからすみやかに隔離します。

### 修復と再建

* **ゼロから作り直す**:環境が侵害された場合、マルウェアがまだ残っている間は、その駆除を試みないでください。その代わりに、既知の良好な状態から環境を完全に再構築します。
* **キャッシュを消去する**:すべてのワークステーションとビルドサーバーで、ローカルと共有のパッケージ マネージャーのキャッシュ(npm、yarn、pnpm)をクリアして、今後のインストール時の再感染を防ぎます。

### 認証情報の包括的ローテーション

* **侵害を想定する**:悪意のあるパッケージが実行された場合、そのマシンでアクセス可能なすべての秘密が盗まれたと考える必要があります。
* **すべての秘密をローテーションする** :npmトークン、AWSアクセス キー、SSHプライベート キー、クラウド環境認証情報(Google Cloud、Azure)、CI/CDシークレット、.envファイルに保存されている機密値など、公開された認証情報をすみやかにローテーションします。

### バージョン管理と依存関係のピンニング

* \*\*Axiosをダウングレードする:\*\*Axiosの安全な最新バージョンにすみやかにダウングレードします:1.14.0または0.30.3。
* **依存関係をピンニングする:** 誤ってアップグレードされないように、package-lock.jsonファイル内でAxiosをこれらの安全なバージョンに固定します。
* **オーバーライドを使用する**:パッケージの設定にオーバーライド ブロックを追加して、悪意のあるバージョンが他のパッケージによって推移的に解決されるのを防いでください。
* **企業リポジトリを制限する**:Axiosの既知の正当なバージョンのみが厳密に提供されるように、企業が管理するnpmリポジトリを設定します。

### ネットワーク防御と監視

* **C2トラフィックをブロックする** :攻撃者のC2ドメイン(sfrclak\[.\]com)とIPアドレス(142.11.206\[.\]73)へのすべてのegressトラフィックをブロックします。
* **ログを監視する**:ポート8000を介した不審なアウトバウンド接続、ビーコン動作、異常なHTTP POSTリクエストをネットワーク ログで監視します。

### CI/CDパイプラインのハードニング

* **CI/CDパイプラインを監査する**:自動ビルド ログを確認し、最近実行されたランの間に、影響を受けるバージョンがインストールされたかどうかを確認します。すべてのシークレットを実行したワークフローをローテーションします。
* **デプロイメントを一時停止し、検証する**: Axiosに依存しているプロジェクトのCI/CDデプロイメントを一時停止し、ビルドが汚染された「最新」バージョンを自動的にプルしていないかどうかを検証します。
* **ライフサイクル スクリプトを無効にする** : CI/CDインストール時に--ignore-scriptsフラグを使用し、自動ビルド時にnpmポストインストール フックの実行を明示的に防ぎます。

### 長期的な開発者セキュリティ

* **サンドボックス環境**:コンテナやサンドボックスを使って開発環境を隔離し、ホストのファイル システムへのアクセスを制限します。
* **Vaultシークレット:** 悪意のあるスクリプトがプログラムでスクレイピングできないように、プレーン テキスト シークレットを開発者のマシンから安全なVaultやOSキーチェーンに移行します(aws-vaultのようなツールを使用)。
* **endpoint detection and response (EDR)をデプロイする**:Node.jsアプリケーションから生成される不審なプロセスを監視するために、開発者のワークステーションにEDRソリューションをデプロイします。

パロアルトネットワークスは、本調査結果をサイバー脅威アライアンス(CTA)のメンバーと共有しています。CTAの会員は、このインテリジェンス情報を利用して、その顧客に対して迅速に保護をデプロイし、悪意のあるサイバー アクターを体系的に阻止しています。[サイバー脅威アライアンス](https://www.cyberthreatalliance.org/)について詳細を見る。

パロアルトネットワークスのお客様は、以下に示す当社製品により保護されています。新たな関連情報が明らかになり次第、本脅威概要は更新されます。

## Axiosサプライ チェーン攻撃に対するパロアルトネットワークス製品の保護機能

パロアルトネットワークスのお客様は、さまざまな製品保護、アップデートを活用して、本脅威を特定し組織を保護いただけます。

情報漏えいの可能性がある場合、または緊急の案件がある場合は[Unit 42インシデント レスポンス チーム](https://start.paloaltonetworks.com/contact-unit42.html)にアクセスするか電話でご連絡ください:

* 北米:フリーダイヤル: +1 (866) 486-4842 (866.4.UNIT42)
* 英国: +44.20.3743.3660
* ヨーロッパおよび中東: +31.20.299.3130
* アジア: +65.6983.8730
* 日本: +81.50.1790.0200
* オーストラリア: +61.2.4062.7950
* インド: 000 800 050 45107
* 韓国: +82.080.467.8774

### Advanced WildFire

[Advanced WildFire](https://docs.paloaltonetworks.com/wildfire)の機械学習モデルと分析技術は、本研究で共有されたインジケーターを考慮してレビューされ、更新されています。

### Advanced Threat Prevention を備えた次世代ファイアウォール

[Advanced Threat Prevention](https://docs.paloaltonetworks.com/dns-security) セキュリティサブスクリプションを適用した[Next-Generation Firewall](https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-new-features/url-filtering-features/advanced-url-filtering)は、以下のスレット プリベンション シグネチャを介して攻撃をブロックするのに役立ちます：[87121](https://threatvault.paloaltonetworks.com/?q=87121)。

### Cortex AgentiX

セキュリティ アナリストは、自然言語を使用して [Cortex AgentiX](https://www.paloaltonetworks.com/cortex/agentix) Threat Intel エージェントに指示（プロンプト）を出し、この脅威ブリーフからファイルの侵害指標（IoC）を抽出できます。その後、それらの情報をエンリッチメントし、自身の Cortex テナント内での検知状況（sightings）や関連するアラートを確認した上で、組織への影響に関する簡潔な要約を提供する必要があります。

### 次世代ファイアウォール向けクラウド提供型セキュリティ サービス

[Advanced URL Filtering](https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-new-features/url-filtering-features/advanced-url-filtering)と[Advanced DNS Security](https://docs.paloaltonetworks.com/dns-security)は、この活動に関連する既知のIPアドレスとドメインを悪意のあるものとして識別することが可能です。

### Cortex XDRおよびXSIAM

[Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR)と[XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM)は、この記事で説明した初期アクセス、C2、潜在的なラテラル ムーブメントから保護するための多層防御を備えています。この多層防御には、Behavioral Threat Protection(BTP)、Advanced WildFire、Cortex Analyticsが含まれます。

具体的には、WindowsとmacOS上における、この攻撃の第2段階に対するAdvanced WildFireとBTPを介したout-of-the-box(OotB)防御を確認しました。以下の記事の説明にあるように、Cortex Analyticsは、当社のカスタマイズされたディテクターを使用して、C2活動や疑わしいサプライ チェーン活動を検出するのに役立ちます:

* [動作分析によるLinux C2と認証情報盗難の阻止方法 - Palo Alto Networks Blog](https://www.paloaltonetworks.com/blog/security-operations/how-behavioral-analytics-stop-linux-c2-credential-theft/)
* [Cortex XDR Global Analyticsによるサプライ チェーン攻撃の防御方法 - Palo Alto Networks Blog](https://www.paloaltonetworks.com/blog/security-operations/how-cortex-xdr-global-analytics-protects-against-supply-chain-attacks/)

最高の保護措置を受けるために、サポートされるバージョンと最新のコンテンツ アップデートにエージェントをアップグレードすることをお勧めします。

### Cortex Cloud

[Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)プラットフォームは、Axios攻撃チェーンの第1段階と第2段階の両方に対して、検知オペレーションと防御オペレーションを提供します。これには、ソフトウェア サプライ チェーン セキュリティ、アプリケーション セキュリティ(AppSec)、クラウド ワークロード プロテクション(CWP)、Cortex XDR、およびXSIAMが含まれます。

CI/CDの信頼できるパブリッシャー検証オペレーションから、ランタイムのインストール後のモニタリングやエンドポイントの永続性検知まで、攻撃のあらゆる段階を、その防止や検知を支援するCortex Cloudの機能にマッピングすることができます。

## 侵害のインジケーター

### SHA256ハッシュ

* ad8ba560ae5c4af4758bc68cc6dcf43bae0e0bbf9da680a8dc60a9ef78e22ff7
* fcb81618bb15edfdedfb638b4c08a2af9cac9ecfa551af135a8402bf980375cf
* cdc05cd30eb53315dadb081a7b942bb876f0d252d20e8ed4d2f36be79ee691fa
* 8449341ddc3f7fcc2547639e21e704400ca6a8a6841ae74e57c04445b1276a10
* 01c9484abc948daa525516464785009d1e7a63ffd6012b9e85b56477acc3e624
* 7b47ed28e84437aee64ffe9770d315c1b984135105f7f608a8b9579517bc0695
* 526ab39d1f56732e4e926715aaa797feb13b1ae86882ec570a4d292e7fdc3699
* a98e04dec3a7fe507eb30c72da808bad60bc14d9d80f9770ec99c438faa85a1a
* 0d83030ab8bfba675fc1661f0756b6770be7dd80b1b718de3d68a01f2e79a5f4
* 92ff08773995ebc8d55ec4b8e1a225d0d1e51efa4ef88b8849d0071230c9645a
* 58401c195fe0a6204b42f5f90995ece5fab74ce7c69c67a24c61a057325af668
* fcb81618bb15edfdedfb638b4c08a2af9cac9ecfa551af135a8402bf980375cf
* e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09
* f7d335205b8d7b20208fb3ef93ee6dc817905dc3ae0c10a0b164f4e7d07121cd
* 617b67a8e1210e4fc87c92d1d1da45a2f311c08d26e89b12307cf583c900d101
* e49c2732fb9861548208a78e72996b9c3c470b6b562576924bcc3a9fb75bf9ff
* 92ff08773995ebc8d55ec4b8e1a225d0d1e51efa4ef88b8849d0071230c9645a
* 506690fcbd10fbe6f2b85b49a1fffa9d984c376c25ef6b73f764f670e932cab4
* 4465bdeaddc8c049a67a3d5ec105b2f07dae72fa080166e51b8f487516eb8d07
* fcb81618bb15edfdedfb638b4c08a2af9cac9ecfa551af135a8402bf980375cf
* 58401c195fe0a6204b42f5f90995ece5fab74ce7c69c67a24c61a057325af668
* 5bb67e88846096f1f8d42a0f0350c9c46260591567612ff9af46f98d1b7571cd
* 59336a964f110c25c112bcc5adca7090296b54ab33fa95c0744b94f8a0d80c0f
* a224dd73b7ed33e0bf6a2ea340c8f8859dfa9ec5736afa8baea6225bf066b248
* 5e2ab672c3f98f21925bd26d9a9bba036b67d84fde0dfdbe2cf9b85b170cab71
* 20df0909a3a0ef26d74ae139763a380e49f77207aa1108d4640d8b6f14cab8ca
* 5b5fbc627502c5797d97b206b6dcf537889e6bea6d4e81a835e103e311690e22
* 506690fcbd10fbe6f2b85b49a1fffa9d984c376c25ef6b73f764f670e932cab4
* 4465bdeaddc8c049a67a3d5ec105b2f07dae72fa080166e51b8f487516eb8d07
* 9c64f1c7eba080b4e5ff17369ddcd00b9fe2d47dacdc61444b4cbfebb23a166c

### IPアドレスとドメイン

* 142\.11.206\[.\]73
* sfrclak\[.\]com
* callnrwise\[.\]com
* hxxp://sfrclak\[.\]com:8000
* hxxp://sfrclak\[.\]com:8000/6202033

*2026年4月1日午後1時15分更新Advanced WildFireのカバレッジを追加するPT。*

*2026年4月9日 午前8時50分（太平洋標準時）更新：Advanced Threat Prevention のカバレッジを追加しました。*

*2026年4月13日 午後12時50分（太平洋標準時）更新：Windows 版における RAT の実行方法を明確化しました。Cortex AgentiX のカバレッジを追加しました。*
トップに戻る

### タグ

* [API attacks](https://unit42.paloaltonetworks.com/ja/tag/api-attacks-ja/ "API attacks")
* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")
* [Powershell](https://unit42.paloaltonetworks.com/ja/tag/powershell-ja/ "Powershell")
* [Supply chain](https://unit42.paloaltonetworks.com/ja/tag/supply-chain-ja/ "supply chain")
* [Trojan](https://unit42.paloaltonetworks.com/ja/tag/trojan-ja/ "Trojan")
* [VBScript](https://unit42.paloaltonetworks.com/ja/tag/vbscript-ja/ "VBScript")  
  [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research") [次ページ:プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/ "プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃")

### 目次

* 

### 関連記事

* [npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/ "article - table of contents")
* [プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/ "article - table of contents")
* [BeyondTrustの深刻な脆弱性（CVE-2026-1731）の悪用においてVShellおよびSparkRATを確認](https://unit42.paloaltonetworks.com/ja/beyondtrust-cve-2026-1731/ "article - table of contents")

## 関連項目 マルウェア リソース

![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年8月6日 [#### ChainDropの脅威の概要:自己増殖型npmワームの内部](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/ja/tag/blockchain-ja/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/ja/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/ja/tag/claude-code/ "Claude code")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/ "ChainDropの脅威の概要:自己増殖型npmワームの内部")  
  ![Pictorial representation of the npm packages supply chain attack. Screen displaying code with a prominent alert symbol and the words 'VIRUS DETECTED' highlighted in red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/05_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年6月2日 [#### npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/ja/tag/credential-harvesting-ja/ "Credential Harvesting")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Npm packages](https://unit42.paloaltonetworks.com/ja/tag/npm-packages/ "npm packages")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/ "npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)")  
  ![Pictorial representation of Screening Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/Serpens-Iran-A-1920x900-2-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)脅威アクター グループ](https://unit42.paloaltonetworks.com/ja/category/threat-actor-groups-ja/) 2026年5月22日 [#### イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/ja/tag/advanced-persistent-threat-ja/ "Advanced Persistent Threat")

* [AppDomainManager](https://unit42.paloaltonetworks.com/ja/tag/appdomainmanager/ "AppDomainManager")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/ "イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡")  
  ![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月17日 [#### 脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/ja/tag/apk-ja/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/ja/tag/ddos-attacks-ja/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/ja/tag/genai-ja/ "GenAI")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/ "脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)")  
  ![Pictorial representation of TeamPCP. Glowing code on a screen where several word such as Crime, Hackers, and Security are highlighted in a contrasting color.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/03_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年3月31日 [#### プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/)

* [CVE-2025-55182](https://unit42.paloaltonetworks.com/ja/tag/cve-2025-55182-ja/ "CVE-2025-55182")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/ "プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃")  
  ![Pictorial representation of phishing campaign. A blurred image focusing on a person typing on a laptop with lines of code visible on the screen, illuminated in blue and red lights, suggestive of intense coding or cyber activities.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/06_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年3月24日 [#### 脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/)

* [Email scam](https://unit42.paloaltonetworks.com/ja/tag/email-scam/ "email scam")

* [Lure](https://unit42.paloaltonetworks.com/ja/tag/lure/ "lure")

* [Phishing](https://unit42.paloaltonetworks.com/ja/tag/phishing-ja/ "phishing")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/ "脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム")  
  ![Pictorial representation of Notepad++ supply chain compromise. A digital rendering of Earth from space, focusing on North and South America. The continents are illuminated in blue, with red lines and dots indicating data connections across various locations. Dark background highlights the vibrant network representation.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/11_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年2月11日 [#### 国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/)

* [Backdoor](https://unit42.paloaltonetworks.com/ja/tag/backdoor-ja/ "backdoor")

* [Cobalt Strike](https://unit42.paloaltonetworks.com/ja/tag/cobalt-strike-ja/ "Cobalt Strike")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/ "国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用")  
  ![Pictorial representation of runtime assembly attacks. Digital artwork of a glowing, futuristic shield disintegrating into small particles, set against a dark blue, bokeh-effect background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/09_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月22日 [#### ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/)

* [API](https://unit42.paloaltonetworks.com/ja/tag/api-ja/ "API")

* [Google](https://unit42.paloaltonetworks.com/ja/tag/google-ja/ "Google")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/ "ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成")  
  ![Pictorial representation of SLOW#TEMPEST campaign. Digital artwork depicting a malware alert symbol on a computer screen, with background of blurred programming code in blue and red colors.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/07_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月2日 [#### Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer](https://unit42.paloaltonetworks.com/ja/vvs-stealer/)

* [Discord](https://unit42.paloaltonetworks.com/ja/tag/discord/ "Discord")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")

* [Python](https://unit42.paloaltonetworks.com/ja/tag/python-ja/ "Python")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/vvs-stealer/ "Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/Unit-42_get-updates-banner.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Unit 42 からの最新情報を取得

## 進化する脅威の状況を常に先取り

メール アドレス

本フォームを送信することにより、[利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)に同意し、[プライバシー ポリシー](https://www.paloaltonetworks.jp/legal-notices/privacy)を承認したことになります。

本サイトは reCAPTCHA で保護されており、Googleの[プライバシー ポリシー](https://policies.google.com/privacy) と[サービス利用規約](https://policies.google.com/terms)が適用されます。

Invalid captcha!
サブスクライブ ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} 製品とサービス

* [AI利用ネットワーク セキュリティ プラットフォーム](https://www.paloaltonetworks.jp/network-security)

* [AIのセキュア バイ デザイン](https://www.paloaltonetworks.jp/precision-ai-security/secure-ai-by-design)

* [Prisma AIRS](https://www.paloaltonetworks.jp/prisma/prisma-ai-runtime-security)

* [AI Access Security](https://www.paloaltonetworks.jp/sase/ai-access-security)

* [クラウド提供型セキュリティ サービス](https://www.paloaltonetworks.jp/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.jp/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.jp/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.jp/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.jp/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/enterprise-iot-security)

* [Medical IoT Security](https://www.paloaltonetworks.jp/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/industrial-ot-security)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [次世代ファイアウォール](https://www.paloaltonetworks.jp/network-security/next-generation-firewall)

* [ハードウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/hardware-firewall-innovations)

* [ソフトウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.jp/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.jp/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.jp/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.jp/network-security/panorama)

* [セキュア アクセス サービス エッジ](https://www.paloaltonetworks.jp/sase)

* [Prisma SASE](https://www.paloaltonetworks.jp/sase)

* [App Acceleration](https://www.paloaltonetworks.jp/sase/app-acceleration)

* [自律型デジタルエクスペリエンス管理](https://www.paloaltonetworks.jp/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.jp/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.jp/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.jp/sase/sd-wan)

* [リモート ブラウザ分離](https://www.paloaltonetworks.jp/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [AI駆動型セキュリティ運用プラットフォーム](https://www.paloaltonetworks.jp/cortex)

* [Cloud Security](https://www.paloaltonetworks.jp/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.jp/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.jp/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.jp/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.jp/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.jp/prisma/cloud)

* [AI駆動型SOC](https://www.paloaltonetworks.jp/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.jp/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.jp/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.jp/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.jp/cortex/cortex-xpanse)

* [Unit 42マネージド ディテクション\&レスポンス](https://www.paloaltonetworks.jp/cortex/managed-detection-and-response)

* [マネージドXSIAM](https://www.paloaltonetworks.jp/cortex/managed-xsiam)

* [次世代のアイデンティティ セキュリティ](https://www.paloaltonetworks.jp/idira)

* [特権アクセス管理](https://www.paloaltonetworks.jp/idira/human/privileged-access-management)

* [アイデンティティ管理とアクセス管理](https://www.paloaltonetworks.jp/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.jp/idira/human/endpoint-privilege-manager)

* [アイデンティティ ガバナンス](https://www.paloaltonetworks.jp/idira/human/identity-governance)

* [従業員パスワード管理](https://www.paloaltonetworks.jp/idira/human/workforce-password-management)

* [エージェンティック アイデンティティ](https://www.paloaltonetworks.jp/idira/agentic)

* [シークレット管理](https://www.paloaltonetworks.jp/idira/machine/secrets-management)

* [統合型シークレット ガバナンス](https://www.paloaltonetworks.jp/idira/machine/unified-secrets-governance)

* [アプリケーションの認証情報配信](https://www.paloaltonetworks.jp/idira/machine/application-credentials-delivery)

* [ベンダーの特権アクセス](https://www.paloaltonetworks.jp/idira/human/vendor-privileged-access)

* [脅威インテリジェンス\&インシデント レスポンス サービス](https://www.paloaltonetworks.jp/unit42)

* [予防評価](https://www.paloaltonetworks.jp/unit42/assess)

* [インシデント レスポンス](https://www.paloaltonetworks.jp/unit42/respond)

* [セキュリティ戦略を変革](https://www.paloaltonetworks.jp/unit42/transform)

* [脅威インテリジェンスについて](https://www.paloaltonetworks.jp/unit42/threat-intelligence-partners)  
  会社名

* [パロアルトネットワークスについて](https://www.paloaltonetworks.jp/about-us)

* [採用情報](https://jobs.paloaltonetworks.com/en/)

* [お問合せ](https://www.paloaltonetworks.jp/company/contact-sales)

* [企業責任](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [お客様向け](https://www.paloaltonetworks.jp/customers)

* [IR](https://investors.paloaltonetworks.com/)

* [拠点](https://www.paloaltonetworks.com/about-us/locations)

* [ニュースルーム](https://www.paloaltonetworks.jp/company/newsroom)  
  人気のあるリンク

* [ブログ](https://www.paloaltonetworks.com/blog/?lang=ja)

* [コミュニティ](https://www.paloaltonetworks.com/communities)

* [コンテンツライブラリ](https://www.paloaltonetworks.jp/resources)

* [Cyberpedia](https://www.paloaltonetworks.jp/cyberpedia)

* [イベントセンター](https://events.paloaltonetworks.com/)

* [電子メール設定の管理](https://start.paloaltonetworks.com/preference-center)

* [製品A〜Z](https://www.paloaltonetworks.jp/products/products-a-z)

* [製品認証](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance)

* [脆弱性の報告](https://www.paloaltonetworks.com/security-disclosure)

* [サイトマップ](https://www.paloaltonetworks.jp/sitemap)

* [テクニカル ドキュメント](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.jp/)

* [個人情報の販売および共有禁止](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [プライバシー](https://www.paloaltonetworks.jp/legal-notices/privacy)

* [トラスト センター](https://www.paloaltonetworks.jp/legal-notices/trust-center)

* [利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)

* [ドキュメント](https://www.paloaltonetworks.jp/legal-notices)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![](https://www.paloaltonetworks.jp/content/dam/pan/en_US/images/icons/podcast.svg)](https://unit42.paloaltonetworks.com/unit-42-threat-vector-podcast/)
* JP  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
