STARDUST CHOLLIMA Likely Compromises Axios npm Package
2026-04-03T07:23:38Z•49ab948780e3bd1f17c0168da55ac92a8486689d58b681442c75dc6c405893cb
DPRKSTARDUST_CHOLLIMAaxiosdependency-poisoningincident-responsejavascriptmalicious-packagemitigationnodejsnpmpackage-compromisesoftware-supply-chainsupply-chainthreat-actorthreat-hunting
What happened
CrowdStrike reports that STARDUST CHOLLIMA likely compromised the widely used Axios npm package. This is a software supply-chain incident affecting a popular Node.js HTTP client library; a compromised Axios package could enable malicious code execution, credential/data exfiltration, persistence, or downstream compromise across many projects that depend on the package. Organizations should assume elevated risk if they consume affected Axios versions, audit and verify package integrity, update or replace compromised packages, rotate secrets, and hunt for related indicators of compromise.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- crowdstrike_blog
- Record identifier
- 49ab948780e3bd1f17c0168da55ac92a8486689d58b681442c75dc6c405893cb
- Enrichment time
- 2026-04-03T07:23:38Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.