‘Hundreds of thousands of stolen secrets may have been exposed as a result of this latest attack’: Google says North Korean hackers behind massive Axios attack



  • Google Threat Intelligence Group warns of supply chain attack on Axios npm library
  • Malicious “plain-crypto-js” dependency installed by WAVESHAPER.V2 backdoor on Windows, macOS, and Linux
  • The points are from the North Korean group UNC1069, which is known for its long-running campaigns targeting cryptocurrency and software developers.

North Korean government-sponsored threat actors are targeting the popular npm package in an attempt to infect its users with malware.

In a security advisory, Google’s Threat Intelligence Group (GTIG) said it was monitoring “active software attacks” targeting Axios, “a JavaScript library widely used to simplify HTTP requests”. Simplify tasks like calling APIs, catching responses, and handling errors compared to using built-in tools like fetch or XMLHttpRequest.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

spot_img

More like this

NordVPN make Meshnet free to use

NordVPN promises urgent Mac app update after users call...

The latest NordVPN macOS update has caused significant interface lag and dropped connections for users.Frustrated customers took...
The Last of Us Part 2 Remastered Joel Miller looking up

A former Xbox boss thinks Naughty Dog’s decision to...

Former Microsoft executive Laura Fryer says Naughty Dog's decision to cancel The Last of Us Online ...
My New Ikea Smart Lamp is a Glowing Donut of Happiness

This Donut Smart Lamp From Ikea Has Super Bright...

Benefits ...