STARDUST CHOLLIMA Likely Compromises Axios npm Package
2026-04-05T07:23:33Z•cff388ee5fbcc8e1d38a1827017f1f5979c2fed4a570b6a1e9980c70b0b4882c
CNAME-abuseCVE-2026-20929ChollimaSTARDUSTai-securityauthentication-relayaxioscertificate-lifecyclecnappcrowdstrike-blogdnsendpoint-securityfalconkerberosmalicious-packagenodejsnpmsecure-bootsupply-chainvulnerability-detection
What happened
CrowdStrike blog roundup (Mar–Apr 2026) highlights a likely supply‑chain compromise: STARDUST CHOLLIMA is reported to have likely compromised the Axios npm package (Apr 1, 2026), a potentially widespread Node.js supply‑chain impact. The feed also includes a technical detection writeup for CVE-2026-20929 (Kerberos authentication relay via DNS CNAME abuse) and multiple product/security posts (Falcon Secure Boot certificate lifecycle management, Falcon Data Security, CNAPP enhancements, AI/agent security and related platform updates).
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- crowdstrike_blog
- Record identifier
- cff388ee5fbcc8e1d38a1827017f1f5979c2fed4a570b6a1e9980c70b0b4882c
- Enrichment time
- 2026-04-05T07:23:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.