The Axios Breach: When npm Trust Becomes an APT Attack Vector
2026-04-06 • Poly Swarm •
https://blog.polyswarm.io/the-axios-breach-when-npm-trust-becomes-an-apt-attack-vector
A compromise of the Axios npm package introduced malicious versions 1.14.1 and 0.30.4 that added a covert dependency and executed a postinstall payload when developers or CI/CD systems installed the package. The excerpt attributes the activity to UNC1069, a North Korea-aligned cluster, citing overlap with WAVESHAPER.V2, infrastructure reuse, and operational similarities with earlier developer-ecosystem targeting. The infection chain used maintainer account takeover, direct npm publishing with a legacy token, obfuscated JavaScript, OS-specific second-stage payloads for macOS, Windows, and Linux, and C2 requests shaped to resemble npm registry traffic. The RAT beacons every 60 seconds with system metadata and supports command execution, payload staging, directory enumeration, and self-termination, while cleanup routines remove obvious traces within seconds. The incident matters because a short exposure window in a widely used dependency could still expose developer workstations, build pipelines, tokens, and downstream production systems.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 617b67a8e1210e4fc87c92d1d1da45a… | 2026-03-30 | 2026-04-17 |
| HASH | 92ff08773995ebc8d55ec4b8e1a225d… | 2026-03-30 | 2026-04-17 |
| HASH | fcb81618bb15edfdedfb638b4c08a2a… | 2026-03-30 | 2026-04-17 |