logo

Supply chain blast: Top npm package backdoored to drop dirty RAT on dev machines

ID: b0a4a43f-be79-5ab8-bcf4-798c82beec2b

STIX ID: report--b0a4a43f-be79-5ab8-bcf4-798c82beec2b

Feed Name: The Register (Security)

Threat Score
92/100

Date Published: 2026-03-31

Date Updated: 2026-04-26

Author: Carly Page

...
...

Attackers hijacked an axios maintainer account and published two poisoned releases ([email protected] and [email protected]) that included a malicious dependency ([email protected]) which executed post-install to fetch and deploy multi-OS RAT payloads; the campaign bypassed CI, staged payloads in advance, attempted to self-destruct traces, and has been attributed by Google to the suspected North Korean actor UNC1069, with affected users urged to assume compromise and remediate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.