Google links Axios npm supply chain attack to North Korea-linked APT UNC1069
2026-04-01T14:51:48Z•c049afd3f4878d4b926030134c97b802920a1665d6f1a4a5734c108696b92ef0
APTAnthropicAxiosCVE-2026-3055Citrix_NetScalerClaude_CodeDow_IncDutch_Ministry_of_FinanceHIUPANKnown_Exploited_VulnerabilitiesLiteLLMLloyds_Banking_GroupMASOL_RATNorth_KoreaPUBLOADPoshRAT','Hypnosis_Loader','FluffyGh0st'QilinSentinelOneSoutheast_AsiaUNC1069data-breachnpmransomwareremote-access-trojansupply-chain
What happened
Multiple high-risk supply-chain and nation-state-linked incidents reported: Google attributes the Axios npm compromise to North Korea-linked APT UNC1069 after attackers hijacked the Axios npm account to publish malicious package updates distributing RATs across Linux, Windows and macOS. SentinelOne autonomously blocked a trojanized LiteLLM package triggered by Claude Code; Anthropic also accidentally leaked the Claude Code source via a public npm release. The U.S. CISA added Citrix NetScaler vulnerability CVE-2026-3055 (CVSS 9.3) to its Known Exploited Vulnerabilities catalog. Other notable事件s
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- c049afd3f4878d4b926030134c97b802920a1665d6f1a4a5734c108696b92ef0
- Enrichment time
- 2026-04-01T14:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.