logo

North Korea-linked hackers suspected in Axios open-source hijack, Google analysts say

ID: 4bc49d78-8a90-51c3-a869-956384f5441b

STIX ID: report--4bc49d78-8a90-51c3-a869-956384f5441b

Feed Name: Nextgov Cybersecurity

Threat Score
90/100

Date Published: 2026-03-31

Date Updated: 2026-04-22

Author: David DiMolfetta

...
...

Google and security researchers report a suspected North Korea-linked group (tracked as UNC1069) compromised the widely used Axios npm package by publishing malicious versions that executed during installation to deploy a cross-platform remote-access trojan; StepSecurity detected and halted the malicious package within hours while Google Threat Intelligence investigates. The incident is a sophisticated supply-chain attack with potential for wide-reaching impact given the package's popularity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.