North Korean threat actor compromises axios npm package.
ID: 47803225-bbef-57cf-9f91-dc2b8ba2bf9e
STIX ID: report--47803225-bbef-57cf-9f91-dc2b8ba2bf9e
Feed Name: The CyberWire
Top stories: A North Korea–linked actor (UNC1069) briefly poisoned two widely used axios npm releases with an obfuscated dropper that deploys the WAVESHAPER.V2 backdoor across Windows, macOS, and Linux, creating broad supply-chain risk; separately, attackers leveraged credentials stolen via the Trivy supply-chain compromise (malicious GitHub Action) to access Cisco development assets, exposing AWS keys, hundreds of repositories, source code and potentially millions of PII records; Airbus announced the acquisition of Ultra Cyber (business item).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
