logo

North Korea’s hijack of one of the web’s most used open source projects was likely weeks in the making

ID: f510e0c7-97b9-5289-899e-7b6cd3b192bb

STIX ID: report--f510e0c7-97b9-5289-899e-7b6cd3b192bb

Feed Name: TechCrunch Security News

Threat Score
90/100

Date Published: 2026-04-06

Date Updated: 2026-04-23

Author: Zack Whittaker

...
...

A suspected North Korean state-backed campaign compromised the popular Axios open-source project by building trust via fake company profiles and a Slack workspace, tricking the maintainer into installing malware during a web meeting and then publishing two malicious Axios packages (pulled ~3 hours later). The brief supply-chain attack may have exposed private keys, credentials, and passwords for systems that installed the compromised releases, illustrating sophisticated social-engineering tactics used to steal cryptocurrency and data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.