CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 318

As cited

Copy frozen at (site build).

threat intel

North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack

Google's Threat Intelligence Group identified a supply chain attack where the widely-used Axios NPM package was compromised with a malicious dependency called plain-crypto-js, injected into versions 1.14.1 and 0.30.4 on March 31, 2026. The threat actor, attributed to UNC1069 (a North Korea-nexus group), deployed the WAVESHAPER.V2 backdoor across Windows, macOS, and Linux systems through a postinstall hook that executed an obfuscated dropper. The attacker gained access by compromising the axios maintainer account and modified package.json to enable silent execution during installation of the affected versions.

Why it matters: Axios is downloaded over 100 million times weekly, making this a critical supply chain risk requiring immediate patching and verification of installed versions across development and production environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack

Google's Threat Intelligence Group identified a supply chain attack where the widely-used Axios NPM package was compromised with a malicious dependency called plain-crypto-js, injected into versions 1.14.1 and 0.30.4 on March 31, 2026. The threat actor, attributed to UNC1069 (a North Korea-nexus group), deployed the WAVESHAPER.V2 backdoor across Windows, macOS, and Linux systems through a postinstall hook that executed an obfuscated dropper. The attacker gained access by compromising the axios maintainer account and modified package.json to enable silent execution during installation of the affected versions.

Why it matters: Axios is downloaded over 100 million times weekly, making this a critical supply chain risk requiring immediate patching and verification of installed versions across development and production environments.

VendorsMicrosoftAppleGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary