Axios npm hack used fake Teams error fix to hijack maintainer account
2026-04-05T07:23:24Z•9020777c69dfc992394bc48a3004bd124170ce4f8dfd4f3d0ed38f9ae878b067
BrowserGateClaude Code leakEU cloud breachExchange OnlineIP reputationNorth KoreaOAuth Device FlowProgress ShareFileQilinWindows forced upgradeZendeskbrowser extensionscrypto theftdevice‑code phishinginfostealer (Vidar)multi‑extortionnpm supply‑chainpre‑auth RCEransomwareresidential proxiessocial engineeringteamPCPthird‑party breach
What happened
Collection of BleepingComputer reports (Apr 2–4, 2026) detailing multiple high‑impact incidents and trends: an Axios npm package maintainer was social‑engineered (fake Teams error fix) — attributed to likely North Korean actors — to hijack a maintainer account; device‑code OAuth phishing attacks surged ~37x as new kits spread; LinkedIn (BrowserGate) was found scanning visitors for >6,000 Chrome extensions and collecting device data; Hims & Hers warns of a data breach after Zendesk ticket theft; Die Linke hit by Qilin ransomware with data theft threats; CERT‑EU attributes a European Commission/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 9020777c69dfc992394bc48a3004bd124170ce4f8dfd4f3d0ed38f9ae878b067
- Enrichment time
- 2026-04-05T07:23:24Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.