Cybersecurity — 2026-04-05
Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069; Backdoor Hit 100M+ Weekly Downloads
Google's Threat Intelligence Group attributed the supply chain compromise of the
Analysis
The use of deepfaked founder identity to social-engineer a maintainer represents a new sophistication threshold for supply chain attacks. The Axios package's 100M+ weekly downloads meant the WAVESHAPER backdoor had a potential blast radius encompassing most major JavaScript applications. The sub-three-hour window before removal limited actual compromise, but the attack vector will be replicated.
The use of deepfaked founder identity to social-engineer a maintainer represents a new sophistication threshold for supply chain attacks. The Axios package's 100M+ weekly downloads meant the WAVESHAPER backdoor had a potential blast radius encompassing most major JavaScript applications. The sub-three-hour window before removal limited actual compromise, but the attack vector will be replicated.