UNC1069 activity affects axios (npm package)

On March 31, 2026, North Korean threat actor UNC1069 compromised the maintainer account of the Axios npm package, a widely used HTTP client library with over.

Part of the PlainSec briefing for 2026-04-05

Sources