North Korea-Linked Hackers Hit Axios npm in Supply Chain Attack
ID: 554a141d-b6f7-5d15-a60e-a04fa5fd052d
STIX ID: report--554a141d-b6f7-5d15-a60e-a04fa5fd052d
Feed Name: GBHackers
A supply-chain compromise of the Axios npm package on 2026-03-31 used stolen maintainer credentials to push updates containing ZshBucket malware across macOS, Linux, and Windows; the malware now supports a unified JSON-based command protocol and expanded post-exploitation capabilities. CrowdStrike attributes the activity with moderate confidence to DPRK-linked STARDUST CHOLLIMA and identifies infrastructure (sfrclak.com and related IPs) overlapping prior Chollima operations; organizations are advised to audit dependencies and tighten access controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
