• Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Login
Join Free
Home
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Coming Soon
Job Board
Events
Contact Awards
USMC Deception Manual
Login
Join Free
Home Global Operations

North Korean Hackers Inject Malware Into Axios npm Package Used by Millions of Developers

  • SOFX Staff Writer
  • April 1, 2026
(Collagery / Shutterstock)
Share on FacebookShare on TwitterLinkedIn

North Korean threat actors compromised the Axios npm package on March 30, 2026, injecting a cross-platform remote access trojan (RAT) into a JavaScript library with roughly 100 million weekly downloads, Google Threat Intelligence Group (GTIG) said Tuesday.

GTIG attributed the attack to UNC1069, a financially motivated group Mandiant has tracked since at least 2018. The group had previously used AI-generated deepfake videos and fabricated meeting invitations to target executives at cryptocurrency and decentralized finance firms.

Google Threat Intelligence Group is tracking an active supply chain attack 🔎

North Korea-nexus actor UNC1069 compromised the “axios” NPM package (v1.14.1 & 0.30.4), deploying the WAVESHAPER.V2 backdoor across Windows, macOS, and Linux.

Learn more: https://t.co/pII35aPpRA pic.twitter.com/pFGWWOpacU

— Mandiant (part of Google Cloud) (@Mandiant) April 1, 2026


The Axios compromise marks a departure from that playbook. Rather than hunting individuals at specific companies, UNC1069 embedded malicious code into shared build infrastructure used across the global developer ecosystem.

Attackers gained access to the npm account of a lead Axios maintainer and published two malicious versions, [email protected] and [email protected]. Both versions silently pulled in a newly created dependency, [email protected], which automated malware detection systems confirmed as the payload carrier.

The compromised releases bypassed the project’s standard deployment pipeline. Axios version 1.14.0 remained the most recent tag visible on GitHub, while the poisoned versions were pushed directly to the npm registry without corresponding repository tags.

The malicious dependency was published to npm at 23:59:12 UTC on March 30. Socket’s automated detection flagged the package at 00:05:41 UTC on March 31, and npm removed both compromised versions by 03:29 UTC, a window of roughly three hours.

Wiz estimates Axios is present in approximately 80% of cloud and code environments. The firm observed the malicious versions in about 3% of the environments it scanned.

“The incident could have far-reaching impacts,” GTIG chief analyst John Hultquist said.

New supply chain attack this time for npm axios, the most popular HTTP client library with 300M weekly downloads.

Scanning my system I found a use imported from googleworkspace/cli from a few days ago when I was experimenting with gmail/gcal cli. The installed version (luckily)… https://t.co/9DOVWH5KK1

— Andrej Karpathy (@karpathy) March 31, 2026


The RAT dropper cleans up after execution. Post-infection inspection of the installed package directory shows no postinstall script or setup.js file, making npm audit and manual review unreliable detection methods.

Confirmed indicators of compromise include the domain sfrclak[.]com and the IP address 142.11.206.73. Developers whose environments pulled the affected versions should treat those systems as fully compromised and immediately rotate all credentials, deploy keys, and API tokens.

How attackers obtained the maintainer’s credentials has not been confirmed. GTIG noted the incident is separate from another npm supply chain attack disclosed the prior week.

SOFX Staff Writer

SOFX Staff Writer

The Editor Staff at SOFX comprises a diverse, global team of dedicated staff writers and skilled freelancers. Together, they form the backbone of our reporting and content creation.

Subscribe
Login
Notify of
guest
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
ADVERTISEMENT

Trending News

Video Captures Navy Super Hornet Narrowly Dodging Iranian Missile

Video Captures Navy Super Hornet Narrowly Dodging Iranian Missile

by SOFX Staff Writer
March 27, 2026
0

A U.S. Navy F/A-18 Super Hornet narrowly escaped an Iranian man-portable air-defense system (MANPADS) missile while conducting a strafing run...

Trump Threatens to Obliterate Iran’s Oil and Water Infrastructure

Videos From Iraq Show What It’s Like to Be on the Receiving End of an A-10 Warthog Strafing Run

by SOFX Staff Writer
March 31, 2026
0

A series of videos emerging from Iraq over the past several days captures what it looks like, and sounds like,...

Rangers and SEALs Join Thousands of Paratroopers in Middle East Buildup

Rangers and SEALs Join Thousands of Paratroopers in Middle East Buildup

by SOFX Staff Writer
March 31, 2026
0

Several hundred U.S. Special Operations forces, including Army Rangers and Navy SEALs, have arrived in the Middle East, The New...

B-2 Spirit Bombers Depart for Iran with Unidentified Wing Patches Days After Key Comms Upgrade

B-2 Spirit Bombers Depart for Iran with Unidentified Wing Patches Days After Key Comms Upgrade

by SOFX Staff Writer
March 26, 2026
0

Photos released by U.S. Central Command (CENTCOM) on March 24 show two B-2A Spirit stealth bombers departing Whiteman Air Force...

ADVERTISEMENT
ADVERTISEMENT
Next Post
AV Companies Hid Their Human Backstop From the Public, Senate Report Finds

AV Companies Hid Their Human Backstop From the Public, Senate Report Finds

Japan’s First Long-Range Missiles Enter Service as Tomahawk Destroyer Completes Refit

Japan's First Long-Range Missiles Enter Service as Tomahawk Destroyer Completes Refit

997 Morrison Dr. Suite 200, Charleston, SC 29403

News

  • Global Operations
  • Special Interest
  • Industry
  • Global Operations
  • Special Interest
  • Industry

Resources

  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
No Result
View All Result
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Subscribe
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.

Log in to your account

Lost your password?
wpDiscuz