Axios npm hack used fake Teams error fix to hijack maintainer account

2026-04-05T01:23:29Z722f37f08c1187f2b5b79ed039992f7b8dc14b2c91776fa0fb63248ed2aa7d1d
browser-scanningdata-breachdevice-code-phishingdrift-protocolexchange-online-outagegovernance-exploitinfo-stealermail-interceptionmulti-extortionnorth-korean-actorsnpmoauth-device-flowpre-auth-rceprivacy-invasionprogress-sharefileqilinransomwareresidential-proxiessocial-engineeringsupply-chain-attackteampcpvidarzendesk-breach

What happened

A set of high-impact incidents and trends: an Axios maintainer account was hijacked via a social‑engineering campaign attributed to North Korean actors; device‑code phishing (abusing the OAuth 2.0 Device Authorization Grant) has surged ~37x this year; LinkedIn reportedly uses hidden scripts to scan for 6,000+ Chrome extensions and collect device data ("BrowserGate"); Hims & Hers disclosed a data breach after Zendesk support tickets were stolen. Other notable items include Qilin ransomware data theft from German party Die Linke; CERT-EU attributing a European Commission cloud breach to TeamPCP,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
722f37f08c1187f2b5b79ed039992f7b8dc14b2c91776fa0fb63248ed2aa7d1d
Enrichment time
2026-04-05T01:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Axios npm hack used fake Teams error fix to hijack maintainer account · Baitaphish