As cited
Copy frozen at (site build).
threat intel
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack
Google's Threat Intelligence Group identified a supply chain attack where the widely-used Axios NPM package was compromised with a malicious dependency called plain-crypto-js, injected into versions 1.14.1 and 0.30.4 on March 31, 2026. The threat actor, attributed to UNC1069 (a North Korea-nexus group), deployed the WAVESHAPER.V2 backdoor across Windows, macOS, and Linux systems through a postinstall hook that executed an obfuscated dropper. The attacker gained access by compromising the axios maintainer account and modified package.json to enable silent execution during installation of the affected versions.
Why it matters: Axios is downloaded over 100 million times weekly, making this a critical supply chain risk requiring immediate patching and verification of installed versions across development and production environments.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack
Google's Threat Intelligence Group identified a supply chain attack where the widely-used Axios NPM package was compromised with a malicious dependency called plain-crypto-js, injected into versions 1.14.1 and 0.30.4 on March 31, 2026. The threat actor, attributed to UNC1069 (a North Korea-nexus group), deployed the WAVESHAPER.V2 backdoor across Windows, macOS, and Linux systems through a postinstall hook that executed an obfuscated dropper. The attacker gained access by compromising the axios maintainer account and modified package.json to enable silent execution during installation of the affected versions.
Why it matters: Axios is downloaded over 100 million times weekly, making this a critical supply chain risk requiring immediate patching and verification of installed versions across development and production environments.
- Source published
- First seen by Cybersecurity Tracker