logo

UNC1069 Targets Node.js Maintainers via Fake LinkedIn, Slack Profiles

ID: 67661bf2-c3ad-50da-a372-875735099991

STIX ID: report--67661bf2-c3ad-50da-a372-875735099991

Feed Name: HackRead

Threat Score
90/100

Date Published: 2026-04-04

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Security researchers at Socket report UNC1069 is running a targeted campaign against Node.js/npm maintainers using patient social-engineering (fake LinkedIn/Slack profiles and cloned meeting sites) to deliver RATs that enable credential theft and supply-chain compromises — a high-impact threat demonstrated by the Axios npm incident.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.