Google Says North Korean Hacker 'UNC1069' Responsible for Supply Chain Attack on Open-Source Axios

Key summary
The Axios npm package was hijacked on 2026-03-31 and two malicious versions were published that distributed malware with a self-delete feature during installation.
Google attributes the compromise to UNC1069, a North Korea–linked threat actor; investigators found connections from an AstrillVPN node previously used by UNC1069.
Attackers inserted a dependency plain-crypto-js@^4.2.1 into package.json, which launched setup.js on install to start a dropper.
The dropper fetched and ran OS-specific payloads—Windows used VBScript and PowerShell, macOS used AppleScript, and Linux used /tmp/ld.py—to deploy a remote-access Trojan and maintain background persistence.
Maintainer and key developer accounts were compromised and emails replaced to seize update distribution, but the malicious releases were detected and blocked within about three hours.



