Google links Axios npm supply chain attack to North Korea-linked APT UNC1069

2026-04-01T14:51:48Zc049afd3f4878d4b926030134c97b802920a1665d6f1a4a5734c108696b92ef0
APTAnthropicAxiosCVE-2026-3055Citrix_NetScalerClaude_CodeDow_IncDutch_Ministry_of_FinanceHIUPANKnown_Exploited_VulnerabilitiesLiteLLMLloyds_Banking_GroupMASOL_RATNorth_KoreaPUBLOADPoshRAT','Hypnosis_Loader','FluffyGh0st'QilinSentinelOneSoutheast_AsiaUNC1069data-breachnpmransomwareremote-access-trojansupply-chain

What happened

Multiple high-risk supply-chain and nation-state-linked incidents reported: Google attributes the Axios npm compromise to North Korea-linked APT UNC1069 after attackers hijacked the Axios npm account to publish malicious package updates distributing RATs across Linux, Windows and macOS. SentinelOne autonomously blocked a trojanized LiteLLM package triggered by Claude Code; Anthropic also accidentally leaked the Claude Code source via a public npm release. The U.S. CISA added Citrix NetScaler vulnerability CVE-2026-3055 (CVSS 9.3) to its Known Exploited Vulnerabilities catalog. Other notable事件s

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
c049afd3f4878d4b926030134c97b802920a1665d6f1a4a5734c108696b92ef0
Enrichment time
2026-04-01T14:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.