On March 31, 2026, North Korean threat actor UNC1069 compromised the maintainer account of the Axios npm package, a widely used HTTP client library with over.
Part of the PlainSec briefing for 2026-04-05