logo

Axios npm hack used fake Teams error fix to hijack maintainer account

ID: 42f0a8b5-6842-5c2c-bfe3-5b544aa7255a

STIX ID: report--42f0a8b5-6842-5c2c-bfe3-5b544aa7255a

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2026-04-04

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

The Axios HTTP client was subject to a coordinated supply-chain attack after a maintainer was socially engineered via fake Slack/Teams interactions; attackers installed a malicious Teams update (RAT) on the maintainer's device, stole npm credentials, and published two malicious Axios versions (1.14.1 and 0.30.4) that added a dependency installing a remote access trojan across macOS, Windows, and Linux. Google links the operation to North Korean UNC1069 (using WAVESHAPER.V2); the malicious releases were live for roughly three hours, multiple maintainers were targeted using impersonation and fake update prompts, and systems that installed the packages should be treated as compromised with credentials rotated and systems cleaned.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.