logo

North Korea-Linked Hackers Compromise Axios npm Package in Major Supply Chain Attack

ID: a05bb7e6-986b-5f4a-acaa-28b2edce27d8

STIX ID: report--a05bb7e6-986b-5f4a-acaa-28b2edce27d8

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-04-03

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

On March 31, 2026, attackers using stolen maintainer credentials compromised the widely used Axios npm package and injected upgraded variants of the ZshBucket malware; CrowdStrike attributes the campaign with moderate confidence to North Korea-linked STARDUST CHOLLIMA. The cross-platform implant uses a JSON-based command protocol and C2 at sfrclak.com (142.11.206.73) to inject binaries, execute arbitrary scripts, enumerate file systems, and terminate implants, creating a high-impact supply-chain threat to developers and financial/cryptocurrency targets; organizations are advised to audit environments, verify package integrity, rotate maintainer credentials, enable software composition analysis, and investigate any traffic to the listed domain and IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.