Frequently Asked Questions About the Axios npm Supply Chain Attack by North Korea-Nexus Threat Actor UNC1069

2026-04-01T20:52:20Z483f4a9a8658cae4f26ad78b3d5cfa6e5c4995b32fc1d8fec897bc4b0210dc51
North KoreaRATUNC1069WAVESHAPERaxioscredential-theftcross-platformincident-responsenpmnpm-registrypackage-compromiseplain-crypto-jssupply-chain

What happened

On 2026-03-31 a North Korea–nexus threat actor (attributed by Google to UNC1069) compromised the maintainer account for the widely used axios npm package and published malicious versions 1.14.1 and 0.30.4. Those versions included a malicious dependency named “plain-crypto-js” that delivered WAVESHAPER.V2, a cross‑platform remote access trojan (RAT) targeting macOS, Windows and Linux. The poisoned releases were available on the npm registry for ~three hours and potentially reached millions of developer environments. Tenable and other responders removed the malicious versions and advise treating

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
tenable_blog
Record identifier
483f4a9a8658cae4f26ad78b3d5cfa6e5c4995b32fc1d8fec897bc4b0210dc51
Enrichment time
2026-04-01T20:52:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.