logo

North Korean threat actor compromises axios npm package.

ID: 47803225-bbef-57cf-9f91-dc2b8ba2bf9e

STIX ID: report--47803225-bbef-57cf-9f91-dc2b8ba2bf9e

Feed Name: The CyberWire

Threat Score
88/100

Date Published: 2026-04-01

Date Updated: 2026-04-23

...
...

Top stories: A North Korea–linked actor (UNC1069) briefly poisoned two widely used axios npm releases with an obfuscated dropper that deploys the WAVESHAPER.V2 backdoor across Windows, macOS, and Linux, creating broad supply-chain risk; separately, attackers leveraged credentials stolen via the Trivy supply-chain compromise (malicious GitHub Action) to access Cisco development assets, exposing AWS keys, hundreds of repositories, source code and potentially millions of PII records; Airbus announced the acquisition of Ultra Cyber (business item).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.