“Hundreds of thousands of stolen secrets could potentially circulate as a result of these recent attacks”: Google says North Korean hackers behind major attack on Axios


  • Google Threat Intelligence Group Warns of Active Supply Chain Attack Against npm’s Axios Library
  • The “plain-crypto-js” malicious dependency deployed a WAVESHAPER.V2 backdoor on Windows, macOS, and Linux.
  • The attribution points to the North Korean group UNC1069, known for its long-running campaigns targeting cryptocurrency and software developers.

North Korean state-sponsored threat actors are targeting a hugely popular npm package in an attempt to infect its users with malware.

In a security advisory, Google’s Threat Intelligence Group (GTIG) said it was monitoring an “active software supply chain attack” targeting Axios, “the most popular JavaScript library used to simplify HTTP requests.” It simplifies tasks like API calling, response handling, and error handling compared to using built-in tools like fetch or XMLHttpRequest.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top