logo

North Korea’s Lazarus Group Behind the Axios npm Supply Chain Attack

ID: 9377e6b4-0eee-5ac5-bf3f-92d0ee2f1df4

STIX ID: report--9377e6b4-0eee-5ac5-bf3f-92d0ee2f1df4

Feed Name: The Cyber Express

Threat Score
92/100

Date Published: 2026-04-01

Date Updated: 2026-04-23

Author: Mihir Bagwe

...
...

A supply-chain compromise of the popular axios npm package (versions 1.14.1 and 0.30.4) introduced a malicious dependency that executed a postinstall dropper (SILKBELL) and deployed a WAVESHAPER.V2 backdoor across Windows, macOS, and Linux; Google Threat Intelligence Group, ThreatBook, and other firms attribute the campaign to UNC1069/Lazarus, warning of widespread exposure given axios’s massive usage and providing IOCs and remediation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.