Threats · 161 days ago
The Axios supply chain compromise is now a broader campaign targeting multiple high-profile Node.js maintainers, not just a single package. Attackers focus on infecting maintainers’ development machines and gaining publishing access, enabling them to push malicious updates across many packages. This means the real risk lies in compromised maintainer endpoints, which standard package removal does not address.
UNC1069, a North Korean threat actor, uses sophisticated social engineering involving fake Slack workspaces and Microsoft Teams meetings to trick maintainers into installing remote access trojans. This campaign has targeted maintainers of hundreds of widely used npm packages with billions of downloads, including the Axios lead maintainer and others in the Node.js ecosystem. The attackers build trust over weeks before delivering malware, making the attacks highly convincing and scalable.
This shift from a single package compromise to a reusable infection playbook means the blast radius extends across the entire Node.js ecosystem. Compromised maintainers can publish malicious updates to any package they control, increasing the risk to downstream users and highlighting the importance of securing maintainer environments and publishing workflows.
11 sources covering this story
Axios Attack: How Complex Social Engineering Is Industrialized
The attack on the popular NPM package Axios has shone a light on how advanced threat actors can scale sophisticated social engineering campaigns.
North Korean Hackers Target High-Profile Node.js Maintainers
The threat actor behind the Axios supply chain attack has been aiming at other maintainers in its social engineering campaign.
Axios npm hack used fake Teams error fix to hijack maintainer account
The maintainers of the popular Axios HTTP client have published a detailed post-mortem describing how one of its developers was targeted by a social engineering campaign believed to have been conducted by North Korean threat actors.
Attackers Are Hunting High-Impact Node.js Maintainers in a C...
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
Securing the Supply Chain: How SentinelOne®’s AI EDR Stops the Axios Attack Autonomously
A guide to the suspected North Korean cyber attack—and how SentinelOne defends against it at machine speed
Axios Maintainer Confirms Social Engineering Attack Behind n...
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.
How we caught the Axios supply chain attack — Elastic Security Labs
Joe Desimone shares the story of how he caught the Axios supply chain attack with a proof of concept tool built in an afternoon.
Axios npm Supply Chain Attack FAQ: North Korea UNC1069 | Tenable®
North Korea-nexus threat actor UNC1069 compromised the axios npm package, delivering the WAVESHAPER.V2 RAT to macOS, Windows, and Linux systems.
North Korean hackers linked to Axios npm supply chain compromise - Help Net Security
The supply chain attack that lead to the compromise of Axios npm packages is likely the work of financially-motivated North Korean attackers.
Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069
Google links Axios npm supply chain attack to UNC1069 after trojanized versions 1.14.1 and 0.30.4 spread WAVESHAPER.V2, impacting multiple OS.
The Record from Recorded Future
Google links axios supply chain attack to North Korean group
Google Threat Intelligence Group (GTIG) joined several other researchers in attributing the attack to a North Korean threat actor they call UNC1069.
Axios npm package compromised to deploy malware
A supply chain attack targeted Axios
Part of the PlainSec briefing for 2026-04-05