Axios npm hack used fake Teams error fix to hijack maintainer account

2026-04-05T07:23:24Z9020777c69dfc992394bc48a3004bd124170ce4f8dfd4f3d0ed38f9ae878b067
BrowserGateClaude Code leakEU cloud breachExchange OnlineIP reputationNorth KoreaOAuth Device FlowProgress ShareFileQilinWindows forced upgradeZendeskbrowser extensionscrypto theftdevice‑code phishinginfostealer (Vidar)multi‑extortionnpm supply‑chainpre‑auth RCEransomwareresidential proxiessocial engineeringteamPCPthird‑party breach

What happened

Collection of BleepingComputer reports (Apr 2–4, 2026) detailing multiple high‑impact incidents and trends: an Axios npm package maintainer was social‑engineered (fake Teams error fix) — attributed to likely North Korean actors — to hijack a maintainer account; device‑code OAuth phishing attacks surged ~37x as new kits spread; LinkedIn (BrowserGate) was found scanning visitors for >6,000 Chrome extensions and collecting device data; Hims & Hers warns of a data breach after Zendesk ticket theft; Die Linke hit by Qilin ransomware with data theft threats; CERT‑EU attributes a European Commission/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
9020777c69dfc992394bc48a3004bd124170ce4f8dfd4f3d0ed38f9ae878b067
Enrichment time
2026-04-05T07:23:24Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.