183 Million Targets: Inside the North Korean Supply Chain Strike on Axios and the WAVESHAPER Backdoor
ID: e5a0c9d2-a5e6-5ffb-afb9-f205a219b557
STIX ID: report--e5a0c9d2-a5e6-5ffb-afb9-f205a219b557
Feed Name: securityonline.info
Threat Score
GTIG warns that between March 31 and early April 1, 2026, an attacker compromised a maintainer account for the widely used axios NPM package and injected a malicious dependency (plain-crypto-js) into axios versions 1.14.1 and 0.30.4; the package uses a postinstall hook to run an obfuscated dropper (setup.js) that deploys WAVESHAPER.V2, a cross-platform RAT attributed to UNC1069, potentially impacting a vast number of projects and systems that depend on axios.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
