logo

UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack

ID: c4313e35-b65c-5338-82c0-0e0f49bb1560

STIX ID: report--c4313e35-b65c-5338-82c0-0e0f49bb1560

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-04-03

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

The Axios npm package was compromised through a highly targeted social-engineering supply-chain attack attributed to UNC1069 (North Korean actors). Attackers cloned a company's identity, used a branded Slack workspace and a fake Microsoft Teams call to trick the maintainer into installing an update that deployed a remote access trojan, enabling theft of npm credentials and publication of two trojanized Axios releases (1.14.1 and 0.30.4) containing WAVESHAPER.V2; associated malware (CosmicDoor and SilentSiphon) was used to exfiltrate credentials and secrets, creating a large-scale risk given Axios's widespread use (~100 million weekly downloads).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.