Google Attributes Axios Open-Source Hijack to North Korean Hackers – MLQ.ai

Google’s Threat Intelligence Group has attributed a supply chain attack on the popular Axios JavaScript library to North Korean hackers tracked as UNC1069. The incident on March 31, 2026, involved publishing backdoored npm versions that delivered malware to developers’ systems.
Attackers compromised the npm account of Axios maintainer ‘jasonsaayman’ to release versions 1.14.1 and 0.30.4 at 00:21 UTC and 01:00 UTC on March 31, 2026[4]. These versions injected a malicious dependency, [email protected], which deployed a cross-platform remote access trojan targeting Windows, macOS, and Linux. On macOS, the payload used AppleScript to fetch and execute a trojan binary from sfrclak.com:8000, then self-deleted to evade detection[4]. Security firm StepSecurity detected the issue within hours, leading to removal of the packages from npm[1].
Google analyst John Hultquist stated the attack aligns with UNC1069, a North Korean group experienced in supply chain attacks for cryptocurrency theft[1]. The malware connected to a command-and-control server, deployed payloads, and wiped traces, described as one of the most sophisticated attacks on a top-10 npm package[1]. Elastic Security noted overlaps with WAVESHAPER backdoor attributed to UNC1069, and internal references to BlueNoroff’s webT module[3][4].
Axios, used for HTTP requests, has over 100 million weekly downloads and appears in 80% of cloud and code environments per Wiz[2]. Huntress reported over 100 affected devices, while Wiz found malicious versions in 3% of scanned environments[2][3]. Users of the compromised versions must rotate credentials and downgrade to 1.14.0 or 0.30.3[3]. The attack bypassed GitHub Actions CI/CD via a long-lived npm token[4].
The stories that matter, in one email. Free — unsubscribe anytime.
Get the weekly briefing, full research reports, and real-time alerts on the companies you track.
The interconnection queue holds more than 1,100 GW of power. The grid delivers renewables quickly and firm gas slowly, if at all. A model of what the US grid can actually deliver, and when, built on MLQ's queue and generator data.

source

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *