STARDUST CHOLLIMA Likely Compromises Axios npm Package

2026-04-05T07:23:33Zcff388ee5fbcc8e1d38a1827017f1f5979c2fed4a570b6a1e9980c70b0b4882c
CNAME-abuseCVE-2026-20929ChollimaSTARDUSTai-securityauthentication-relayaxioscertificate-lifecyclecnappcrowdstrike-blogdnsendpoint-securityfalconkerberosmalicious-packagenodejsnpmsecure-bootsupply-chainvulnerability-detection

What happened

CrowdStrike blog roundup (Mar–Apr 2026) highlights a likely supply‑chain compromise: STARDUST CHOLLIMA is reported to have likely compromised the Axios npm package (Apr 1, 2026), a potentially widespread Node.js supply‑chain impact. The feed also includes a technical detection writeup for CVE-2026-20929 (Kerberos authentication relay via DNS CNAME abuse) and multiple product/security posts (Falcon Secure Boot certificate lifecycle management, Falcon Data Security, CNAPP enhancements, AI/agent security and related platform updates).

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
crowdstrike_blog
Record identifier
cff388ee5fbcc8e1d38a1827017f1f5979c2fed4a570b6a1e9980c70b0b4882c
Enrichment time
2026-04-05T07:23:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.