Tradecraft Tuesday Recap: axios npm Supply Chain Compromise
ID: f72b2fe4-959f-5454-b1d5-b88201288f58
STIX ID: report--f72b2fe4-959f-5454-b1d5-b88201288f58
Feed Name: Huntress Blog
Threat Score
A March supply-chain compromise of the widely used axios npm package involved two malicious releases that delivered a cross-platform RAT capable of reconnaissance, credential theft, and remote execution; Google attributed the attack to UNC1069 and researchers observed active infections and tracked IoCs, prompting guidance on dependency pinning, vetting, and other supply-chain mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
