logo

Frequently Asked Questions About the Axios npm Supply Chain Attack by North Korea-Nexus Threat Actor UNC1069

ID: cee8b75e-7651-51e3-96b4-843c6d9bd4d2

STIX ID: report--cee8b75e-7651-51e3-96b4-843c6d9bd4d2

Feed Name: Tenable Blog

Threat Score
90/100

Date Published: 2026-04-01

Date Updated: 2026-05-01

Author: Research Special Operations

...
...

**Executive summary:** On March 31, a threat actor compromised the widely used axios npm package and published two malicious versions containing a malicious dependency (plain-crypto-js) whose postinstall dropper (SILKBELL) deployed the WAVESHAPER.V2 backdoor to macOS, Windows and Linux systems; Google Threat Intelligence Group attributes the campaign to UNC1069, the malicious packages were live for ~three hours, IoCs and mitigation steps (credential rotation, rebuilds, blocking C2s, detection rules) are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.