Hackers Launch Social Engineering Offensive Against Key Node.js Maintainers
ID: 65da11f0-bd9f-5698-8756-75054b453ce8
STIX ID: report--65da11f0-bd9f-5698-8756-75054b453ce8
Feed Name: GBHackers
Following a supply-chain compromise of the Axios package, researchers uncovered a sophisticated social‑engineering campaign targeting top Node.js/npm maintainers: attackers use LinkedIn/Slack lures and spoofed video conferencing to induce victims to run a payload that installs a persistent Remote Access Trojan which captures post-authentication state (session cookies, AWS credentials, publishing tokens) to obtain npm registry write access; the operation is linked to UNC1069 and poses a severe risk of widespread malicious package distribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
