North Korean hackers blamed for hijacking popular Axios open source project to spread malware
ID: 962a79b3-62b2-5575-8814-44131c558c24
STIX ID: report--962a79b3-62b2-5575-8814-44131c558c24
Feed Name: TechCrunch Security News
Threat Score
A suspected North Korean-linked threat actor (tracked as UNC1069) hijacked a maintainer account for the popular Axios npm package and pushed malicious releases containing a remote access trojan (RAT). The compromise was active for approximately three hours before being stopped; the malware was designed to auto-delete to evade detection, and investigators caution that users who installed the affected versions should assume their systems are compromised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
