‘Hundreds of thousands of stolen secrets may have been exposed as a result of this latest attack’: Google says North Korean hackers behind massive Axios attack



  • Google Threat Intelligence Group warns of supply chain attack on Axios npm library
  • Malicious “plain-crypto-js” dependency installed by WAVESHAPER.V2 backdoor on Windows, macOS, and Linux
  • The points are from the North Korean group UNC1069, which is known for its long-running campaigns targeting cryptocurrency and software developers.

North Korean government-sponsored threat actors are targeting the popular npm package in an attempt to infect its users with malware.

In a security advisory, Google’s Threat Intelligence Group (GTIG) said it was monitoring “active software attacks” targeting Axios, “a JavaScript library widely used to simplify HTTP requests”. Simplify tasks like calling APIs, catching responses, and handling errors compared to using built-in tools like fetch or XMLHttpRequest.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

spot_img

More like this

NYT Strands homescreen on a mobile phone screen, on a light blue background

NYT Strands Hints and Answers for Sunday, April 19...

Looking for a different day?A new NYT Strands puzzle appears at midnight each day in your time...
NordVPN make Meshnet free to use

NordVPN promises urgent Mac app update after users call...

The latest NordVPN macOS update has caused significant interface lag and dropped connections for users.Frustrated customers took...
The Best Smart Devices Powered by Amazon Alexa and Alexa Plus in 2026

The Best Smart Devices Powered by Amazon Alexa and...

Alexa PlusAlexa Plus is Amazon's AI version of Alexa. It's very talkative, can...