logo

Hackers Launch Social Engineering Offensive Against Key Node.js Maintainers

ID: 65da11f0-bd9f-5698-8756-75054b453ce8

STIX ID: report--65da11f0-bd9f-5698-8756-75054b453ce8

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-04-04

Date Updated: 2026-04-22

Author: Divya

...
...

Following a supply-chain compromise of the Axios package, researchers uncovered a sophisticated social‑engineering campaign targeting top Node.js/npm maintainers: attackers use LinkedIn/Slack lures and spoofed video conferencing to induce victims to run a payload that installs a persistent Remote Access Trojan which captures post-authentication state (session cookies, AWS credentials, publishing tokens) to obtain npm registry write access; the operation is linked to UNC1069 and poses a severe risk of widespread malicious package distribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.