logo

Google links axios supply chain attack to North Korean group

ID: ff93dc26-08f1-5a23-be44-385ad271e474

STIX ID: report--ff93dc26-08f1-5a23-be44-385ad271e474

Feed Name: The Record from Recorded Future News

Threat Score
90/100

Date Published: 2026-03-31

Date Updated: 2026-05-01

...
...

Researchers report a supply-chain attack on the widely used npm package axios in which attackers hijacked a maintainer account to publish malicious package versions that deployed a multi-stage RAT across Windows, macOS, and Linux. Google Threat Intelligence and others attribute the activity to a North Korean actor (UNC1069); the malware executed, exfiltrated data, persisted, then replaced itself with legitimate files to evade detection, creating a broad and sophisticated risk to organizations that depend on axios.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.