North Korea Poisons Axios NPM with RATs in Bold Supply Chain Hit
A single hijacked maintainer turned Axios—the JS HTTP king with 100 million weekly downloads—into a RAT delivery vehicle. North Korean actors bet big on supply chain chaos, and it almost paid off.
Threat DigestApr 03, 20264 min read
⚡ Key Takeaways
Axios hijack via maintainer compromise spreads cross-platform RATs to millions of projects.𝕏
Check lockfiles immediately for v1.14.1, v0.30.4, or plain-crypto-js—Google warns of huge blast radius.𝕏
North Korea's UNC1069 eyes supply chains; expect provenance mandates to combat this.𝕏
The 60-Second TL;DR
Axios hijack via maintainer compromise spreads cross-platform RATs to millions of projects.
Check lockfiles immediately for v1.14.1, v0.30.4, or plain-crypto-js—Google warns of huge blast radius.
North Korea's UNC1069 eyes supply chains; expect provenance mandates to combat this.