North Korean hackers linked to Axios npm supply chain compromise
ID: 7e05fe96-7b42-5dd0-9d7a-8f666a88a0b8
STIX ID: report--7e05fe96-7b42-5dd0-9d7a-8f666a88a0b8
Feed Name: Help Net Security
A short-lived but high-impact software supply chain attack saw two malicious Axios npm releases that included a hidden post-install dependency which retrieved and executed WAVESHAPER.V2 backdoors (macOS C++ variant plus PowerShell/Python variants for Windows/Linux). GTIG and Mandiant attributed the operation to UNC1069 (North Korea-linked), identified related C2 infrastructure (sfrclak.com -> 142.11.206.73) and noted that even a ~3-hour exposure could impact many downstream projects and CI/CD pipelines.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
