Google links axios supply chain attack to North Korean group
ID: ff93dc26-08f1-5a23-be44-385ad271e474
STIX ID: report--ff93dc26-08f1-5a23-be44-385ad271e474
Feed Name: The Record from Recorded Future News
Researchers report a supply-chain attack on the widely used npm package axios in which attackers hijacked a maintainer account to publish malicious package versions that deployed a multi-stage RAT across Windows, macOS, and Linux. Google Threat Intelligence and others attribute the activity to a North Korean actor (UNC1069); the malware executed, exfiltrated data, persisted, then replaced itself with legitimate files to evade detection, creating a broad and sophisticated risk to organizations that depend on axios.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
