Mitigating the Axios npm supply chain compromise
2026-04-02T02:52:23Z•3f4fe0301dd174cd00c633d48d9e333c66f5b604e93547e6698b93c1a6d62591
AI‑securityCI/CDGPOMSINorth KoreaOWASPSapphire SleetVBScriptagentic‑AIaxiosbackdoorcredential‑stealercritical‑infrastructuredefenderhigh‑value‑assetsidentity‑securityincident‑responsemalwaremitigationnpmransomwaresupply-chaintrivywhatsapp
What happened
Microsoft Security Blog (late March–early April 2026) highlights multiple high‑impact threats and mitigations: a March 31 Axios npm supply‑chain compromise—two malicious npm packages (now removed) that downloaded from C2 and attributed to North Korean actor Sapphire Sleet—potentially exposed hundreds to millions of users; guidance for detecting and responding to a Trivy distribution compromise that injected credential‑stealing malware into CI/CD pipelines worldwide; a WhatsApp‑delivered campaign using VBScript and cloud‑hosted payloads to install MSI backdoors; and additional advisories on the
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 3f4fe0301dd174cd00c633d48d9e333c66f5b604e93547e6698b93c1a6d62591
- Enrichment time
- 2026-04-02T02:52:23Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.