Google links Axios npm supply chain attack to North Korea-linked APT UNC1069
ID: 407fc2ee-3b5f-589c-91e0-07dd47d45878
STIX ID: report--407fc2ee-3b5f-589c-91e0-07dd47d45878
Feed Name: Security Affairs
Threat Score
*Google attributes a recent npm supply-chain compromise of the widely used Axios library to North Korea-linked UNC1069; malicious Axios releases (1.14.1 and 0.30.4) inserted a dependency that deployed WAVESHAPER.V2, a cross-platform remote access trojan which communicated with C2 infrastructure (sfrclak.com -> 142.11.206.73) and could impact many downstream projects and developers.*
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
