logo

North Korea Hack Targets Axios JavaScript Library in Supply Chain Attack

ID: 2b18ed12-e317-5af0-b343-8bb7c9508b4c

STIX ID: report--2b18ed12-e317-5af0-b343-8bb7c9508b4c

Feed Name: ThreatCluster

Threat Score
88/100

Date Published: 2026-03-31

Date Updated: 2026-04-01

...
...

On March 31, 2026, Google Threat Intelligence Group reported that North Korean actor UNC1069 carried out a supply-chain attack against the widely used Axios JavaScript library by publishing a malicious dependency ('plain-crypto-js') into Axios versions 1.14.1 and 0.30.4; the dependency, downloaded millions of times, contained an obfuscated dropper that deployed the WAVESHAPER.V2 backdoor across Windows, macOS, and Linux, and was detected and halted by StepSecurity within hours of deployment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.