STARDUST CHOLLIMA Likely Compromises Axios npm Package
2026-04-06T19:23:45Z•a9d621b650653d460566b3dd1185692ce9f9552bc2aa4a32ad034d6a7e0476b7
AI-securityCNAME-abuseCNAPPCVE-2026-20929DPRKFalconSIEMSTARDUST CHOLLIMAaxiosdetectionkerberosnation-statenpmsecure-bootsupply-chain
What happened
CrowdStrike published a set of blog posts (Mar–Apr 2026) including a high-impact advisory that STARDUST CHOLLIMA likely compromised the widely used Axios npm package, indicating a significant supply‑chain risk to Node.js ecosystems. The feed also includes detection guidance for CVE-2026-20929 (Kerberos authentication relay via DNS CNAME abuse), plus product and capability announcements (Windows Secure Boot certificate lifecycle support in Falcon for IT, Falcon Data Security, CNAPP risk prioritization, Falcon Next‑Gen SIEM, AI/agent security, and managed services). Organizations should treat a潜
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- crowdstrike_blog
- Record identifier
- a9d621b650653d460566b3dd1185692ce9f9552bc2aa4a32ad034d6a7e0476b7
- Enrichment time
- 2026-04-06T19:23:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.