MalwareHigh

North Korean Hackers Compromise Axios npm Package in Supply Chain Attack

Wednesday, April 1, 2026
Global
The Hacker News

Summary

Google attributed the supply chain compromise of the widely-used Axios npm package to North Korean threat cluster UNC1069. Attackers pushed two trojanized versions (1.14.1 and 0.30.4) containing a malicious dependency that delivers a cross-platform backdoor targeting Windows, macOS, and Linux systems.

Threat Analysis

Google's Threat Intelligence Group formally attributed the Axios npm supply chain attack to UNC1069, a financially motivated North Korean threat activity cluster with a history of targeting cryptocurrency and software supply chains. The attackers gained control of the Axios package maintainer's npm account and published two malicious versions (1.14.1 and 0.30.4) that introduced a dependency called 'plain-crypto-js'. This dependency served as a loader for a cross-platform backdoor capable of executing on Windows, macOS, and Linux systems. Axios is one of the most popular JavaScript HTTP client libraries with hundreds of millions of weekly downloads, making the potential impact of this compromise extremely broad. The backdoor is designed to steal cryptocurrency assets and sensitive credentials. Organizations should audit their npm dependency trees for the affected Axios versions, check for the presence of 'plain-crypto-js' in their node_modules, and scan systems for indicators of compromise. Rotate any credentials or API keys that may have been exposed in affected environments. This incident underscores the critical importance of software supply chain security and dependency integrity verification.

Last updated: Apr 1, 2026, 08:23 AM

Daily Intelligence

Stay Ahead of Threats

Subscribe to receive daily threat briefings delivered to your inbox. Be the first to know about emerging security risks.

No spamUnsubscribe anytimeDaily at 9 AM