Frequently Asked Questions About the Axios npm Supply Chain Attack by North Korea-Nexus Threat Actor UNC1069
2026-04-01T20:52:20Z•483f4a9a8658cae4f26ad78b3d5cfa6e5c4995b32fc1d8fec897bc4b0210dc51
North KoreaRATUNC1069WAVESHAPERaxioscredential-theftcross-platformincident-responsenpmnpm-registrypackage-compromiseplain-crypto-jssupply-chain
What happened
On 2026-03-31 a North Korea–nexus threat actor (attributed by Google to UNC1069) compromised the maintainer account for the widely used axios npm package and published malicious versions 1.14.1 and 0.30.4. Those versions included a malicious dependency named “plain-crypto-js” that delivered WAVESHAPER.V2, a cross‑platform remote access trojan (RAT) targeting macOS, Windows and Linux. The poisoned releases were available on the npm registry for ~three hours and potentially reached millions of developer environments. Tenable and other responders removed the malicious versions and advise treating
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- tenable_blog
- Record identifier
- 483f4a9a8658cae4f26ad78b3d5cfa6e5c4995b32fc1d8fec897bc4b0210dc51
- Enrichment time
- 2026-04-01T20:52:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.