Cybersecurity — 2026-04-05

Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069; Backdoor Hit 100M+ Weekly Downloads

Google's Threat Intelligence Group attributed the supply chain compromise of the Axios npm package, with over 100 million weekly downloads, to North Korean threat actor UNC1069. The attackers social-engineered a maintainer using a deepfaked identity of a legitimate company founder, then injected the WAVESHAPER.V2 backdoor via a malicious dependency across Windows, macOS, and Linux. The compromised versions were available for under three hours on March 31 before removal. Microsoft independently attributed the attack to Sapphire Sleet. The incident represents the second major DPRK crypto/supply-chain operation in a single week alongside the $285M Drift Protocol hack.

Analysis
The use of deepfaked founder identity to social-engineer a maintainer represents a new sophistication threshold for supply chain attacks. The Axios package's 100M+ weekly downloads meant the WAVESHAPER backdoor had a potential blast radius encompassing most major JavaScript applications. The sub-three-hour window before removal limited actual compromise, but the attack vector will be replicated.
2 sources
  1. UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack - The Hacker News
  2. North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack - Google Cloud Blog

View in full brief →

UNCLASSIFIED // OPEN SOURCE