“Hundreds of thousands of stolen secrets could potentially circulate as a result of these recent attacks”: Google says North Korean hackers behind major attack on Axios


  • Google Threat Intelligence Group warns of active supply chain attack on npm’s Axios library
  • Malicious dependency “plain-crypto-js” deployed WAVESHAPER.V2 backdoor across Windows, macOS and Linux
  • Attribution points to North Korea’s UNC1069 group, known for long-running campaigns targeting cryptocurrency and software developers

North Korean state-sponsored threat actors are targeting a hugely popular npm package in an attempt to infect its users with malware.

In a security advisory, Google’s Threat Intelligence Group (GTIG) said it was monitoring an “active software supply chain attack” targeting Axios, “the most popular JavaScript library used to simplify HTTP requests”. It simplifies tasks such as calling APIs, handling responses, and handling errors compared to using built-in tools such as fetch or XMLHttpRequest.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top