logo

North Korea-Linked Hackers Hit Axios npm in Supply Chain Attack

ID: 554a141d-b6f7-5d15-a60e-a04fa5fd052d

STIX ID: report--554a141d-b6f7-5d15-a60e-a04fa5fd052d

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-04-03

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A supply-chain compromise of the Axios npm package on 2026-03-31 used stolen maintainer credentials to push updates containing ZshBucket malware across macOS, Linux, and Windows; the malware now supports a unified JSON-based command protocol and expanded post-exploitation capabilities. CrowdStrike attributes the activity with moderate confidence to DPRK-linked STARDUST CHOLLIMA and identifies infrastructure (sfrclak.com and related IPs) overlapping prior Chollima operations; organizations are advised to audit dependencies and tighten access controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.