Axios npm hack used fake Teams error fix to hijack maintainer account
2026-04-05T01:23:29Z•722f37f08c1187f2b5b79ed039992f7b8dc14b2c91776fa0fb63248ed2aa7d1d
browser-scanningdata-breachdevice-code-phishingdrift-protocolexchange-online-outagegovernance-exploitinfo-stealermail-interceptionmulti-extortionnorth-korean-actorsnpmoauth-device-flowpre-auth-rceprivacy-invasionprogress-sharefileqilinransomwareresidential-proxiessocial-engineeringsupply-chain-attackteampcpvidarzendesk-breach
What happened
A set of high-impact incidents and trends: an Axios maintainer account was hijacked via a social‑engineering campaign attributed to North Korean actors; device‑code phishing (abusing the OAuth 2.0 Device Authorization Grant) has surged ~37x this year; LinkedIn reportedly uses hidden scripts to scan for 6,000+ Chrome extensions and collect device data ("BrowserGate"); Hims & Hers disclosed a data breach after Zendesk support tickets were stolen. Other notable items include Qilin ransomware data theft from German party Die Linke; CERT-EU attributing a European Commission cloud breach to TeamPCP,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 722f37f08c1187f2b5b79ed039992f7b8dc14b2c91776fa0fb63248ed2aa7d1d
- Enrichment time
- 2026-04-05T01:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.