STARDUST CHOLLIMA Likely Compromises Axios npm Package

2026-04-06T19:23:45Za9d621b650653d460566b3dd1185692ce9f9552bc2aa4a32ad034d6a7e0476b7
AI-securityCNAME-abuseCNAPPCVE-2026-20929DPRKFalconSIEMSTARDUST CHOLLIMAaxiosdetectionkerberosnation-statenpmsecure-bootsupply-chain

What happened

CrowdStrike published a set of blog posts (Mar–Apr 2026) including a high-impact advisory that STARDUST CHOLLIMA likely compromised the widely used Axios npm package, indicating a significant supply‑chain risk to Node.js ecosystems. The feed also includes detection guidance for CVE-2026-20929 (Kerberos authentication relay via DNS CNAME abuse), plus product and capability announcements (Windows Secure Boot certificate lifecycle support in Falcon for IT, Falcon Data Security, CNAPP risk prioritization, Falcon Next‑Gen SIEM, AI/agent security, and managed services). Organizations should treat a潜

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
crowdstrike_blog
Record identifier
a9d621b650653d460566b3dd1185692ce9f9552bc2aa4a32ad034d6a7e0476b7
Enrichment time
2026-04-06T19:23:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.