UNC1069 Expands Node.js Supply Chain Attacks Beyond Axios

The Axios supply chain compromise is now a broader campaign targeting multiple high-profile Node.js maintainers, not just a single package. Attackers focus on infecting maintainers’ development machines and gaining publishing access, enabling them to push malicious updates across many packages. This means the real risk lies in compromised maintainer endpoints, which standard package removal does not address. UNC1069, a North Korean threat actor, uses sophisticated social engineering involving fake Slack workspaces and Microsoft Teams meetings to trick maintainers into installing remote access trojans. This campaign has targeted maintainers of hundreds of widely used npm packages with billions of downloads, including the Axios lead maintainer and others in the Node.js ecosystem. The attackers build trust over weeks before delivering malware, making the attacks highly convincing and scalable. This shift from a single package compromise to a reusable infection playbook means the blast radius extends across the entire Node.js ecosystem. Compromised maintainers can publish malicious updates to any package they control, increasing the risk to downstream users and highlighting the importance of securing maintainer environments and publishing workflows.

Part of the PlainSec briefing for 2026-04-01

Every edition of this story: UNC1069 Expands Node.js Supply Chain Attacks Beyond Axios

Sources