Associated with: Crypto Core
First seen: 2023-04 •
Last seen: 2026-05
#Axios • 2026-03
In March 2026, attackers attributed by security researchers to North Korea-linked UNC1069/Sapphire Sleet compromised Axios npm maintainer access and published malicious axios releases 1.14.1 and 0.30.4. The releases added the malicious dependency [email protected], whose postinstall chain downloaded cross-platform payloads targeting developer and CI/CD environments; affected organizations were advised to downgrade, remove the dependency, audit build systems, and rotate exposed secrets.
51
Related Reports
0
Affected Countries
3
Months Since