logo

Attack on axios software developer tool threatens widespread compromises

ID: dd5ba8f3-9cff-5d00-ae40-5f65eff8ab4a

STIX ID: report--dd5ba8f3-9cff-5d00-ae40-5f65eff8ab4a

Feed Name: CyberScoop

Threat Score
88/100

Date Published: 2026-03-31

Date Updated: 2026-04-21

Author: mbracken

...
...

A popular open-source npm package (axios) was briefly compromised after an attacker hijacked the lead maintainer's npm account and published poisoned releases that injected a malicious dependency ([email protected]). The dependency acts as a loader for a cross-platform remote access trojan that scrapes credentials and attempts to destroy forensic artifacts; researchers estimate up to ~600,000 downloads during the window, and Google TIG attributed the incident to suspected North Korean group UNC1069.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.