North Korea-Linked Hackers Compromise Axios npm Package in Major Supply Chain Attack
ID: a05bb7e6-986b-5f4a-acaa-28b2edce27d8
STIX ID: report--a05bb7e6-986b-5f4a-acaa-28b2edce27d8
Feed Name: cybersecurityNews.com
On March 31, 2026, attackers using stolen maintainer credentials compromised the widely used Axios npm package and injected upgraded variants of the ZshBucket malware; CrowdStrike attributes the campaign with moderate confidence to North Korea-linked STARDUST CHOLLIMA. The cross-platform implant uses a JSON-based command protocol and C2 at sfrclak.com (142.11.206.73) to inject binaries, execute arbitrary scripts, enumerate file systems, and terminate implants, creating a high-impact supply-chain threat to developers and financial/cryptocurrency targets; organizations are advised to audit environments, verify package integrity, rotate maintainer credentials, enable software composition analysis, and investigate any traffic to the listed domain and IPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
