Hacking IncidentsHigh

North Korean UNC1069 Compromises Axios npm Package in Supply Chain Attack

Thursday, April 2, 2026
Global
The Hacker News + BleepingComputer

Summary

Google attributed the compromise of the popular Axios npm package to North Korean threat cluster UNC1069. Attackers pushed trojanized versions 1.14.1 and 0.30.4 delivering a cross-platform backdoor via a hijacked npm maintainer account.

Threat Analysis

North Korean UNC1069 compromised Axios npm package (hundreds of millions of weekly downloads). Trojanized versions 1.14.1 and 0.30.4 deliver cross-platform backdoor via malicious 'plain-crypto-js' dependency.

Affected Products: Axios npm package versions 1.14.1 and 0.30.4. Any Node.js project that updated to these versions is potentially compromised.

Exploitation Status: Active supply chain attack.

Recommended Mitigations: (1) Check package.json for Axios versions 1.14.1 or 0.30.4 and upgrade. (2) Audit npm logs for 'plain-crypto-js' dependency. (3) Scan systems for indicators of compromise. (4) Rotate all credentials from affected environments.

Last updated: Apr 2, 2026, 08:23 AM

Daily Intelligence

Stay Ahead of Threats

Subscribe to receive daily threat briefings delivered to your inbox. Be the first to know about emerging security risks.

No spamUnsubscribe anytimeDaily at 9 AM