logo

Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069

ID: f8620c02-b427-50ca-971a-400488daa001

STIX ID: report--f8620c02-b427-50ca-971a-400488daa001

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-04-01

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Google and security vendors attribute a supply-chain compromise of the popular Axios npm package to UNC1069 (suspected North Korean financial actor). Attackers hijacked the maintainer account to publish trojanized Axios releases that install a malicious dependency (plain-crypto-js) which runs a SILKBELL dropper via an npm postinstall hook and deploys WAVESHAPER.V2, a multi-platform backdoor (Windows PowerShell, macOS Mach-O, Linux Python). The campaign demonstrates high sophistication (multi-OS payloads, self-cleaning, rapid dual-release compromise) and includes C2 indicators (sfrclak.com, 142.11.206.73) and recommended mitigations such as auditing dependencies, pinning package versions, isolating infected hosts, blocking C2, and rotating credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.