Cyber & Information Security — 2026-04-02

North Korean Group UNC1069 Attributed in Axios npm Supply Chain Attack Affecting 80% of Cloud Environments

Google formally attributed the compromise of the Axios npm package, downloaded roughly 100 million times per week, to North Korean threat group UNC1069. The attacker hijacked a maintainer account, changed its email to an attacker-controlled address, and published malicious versions containing the WAVESHAPER.V2 backdoor targeting Windows, macOS, and Linux. The compromised versions were live for approximately three hours on March 31. Wiz estimates Axios is present in about 80% of cloud and code environments, though Unit 42 noted the brief exposure window limited the blast radius.

Analysis
UNC1069's compromise of a package with 100M weekly downloads represents a qualitative escalation in DPRK supply chain operations, moving from targeting individual organizations to poisoning shared infrastructure. The 80% cloud environment exposure suggests blast radius may exceed SolarWinds.
1 sources
  1. Threat Brief: Widespread Impact of the Axios Supply Chain Attack - Unit 42

View in full brief →

UNCLASSIFIED // OPEN SOURCE