logo

Google links Axios npm supply chain attack to North Korea-linked APT UNC1069

ID: 407fc2ee-3b5f-589c-91e0-07dd47d45878

STIX ID: report--407fc2ee-3b5f-589c-91e0-07dd47d45878

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-04-01

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

*Google attributes a recent npm supply-chain compromise of the widely used Axios library to North Korea-linked UNC1069; malicious Axios releases (1.14.1 and 0.30.4) inserted a dependency that deployed WAVESHAPER.V2, a cross-platform remote access trojan which communicated with C2 infrastructure (sfrclak.com -> 142.11.206.73) and could impact many downstream projects and developers.*

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.