“Hundreds of thousands of stolen secrets could be circulating as a result of these recent attacks”: Google says North Korean hackers behind major Axios attack



  • Google Threat Intelligence Group warns of active supply chain attack on npm’s Axios library
  • Malicious “plain-crypto-js” dependency implemented WAVESHAPER.V2 backdoor on Windows, macOS, and Linux
  • The attribution points to North Korea’s UNC1069 group, known for long-running campaigns targeting software and cryptocurrency developers.

North Korean state-sponsored threat actors are targeting a popular npm package in an attempt to infect its users with malware.

In a security advisory, Google’s Threat Intelligence Group (GTIG) said it was monitoring an “active software supply chain attack” targeting Axios, “the most popular JavaScript library used to simplify HTTP requests.” It simplifies tasks like calling APIs, handling responses, and managing errors compared to using built-in tools like fetch or XMLHttpRequest.



Leave a Comment

Your email address will not be published. Required fields are marked *