The Axios Breach: When npm Trust Becomes an APT Attack Vector

2026-04-06 Poly Swarm

https://blog.polyswarm.io/the-axios-breach-when-npm-trust-becomes-an-apt-attack-vector

Thumbnail for The Axios Breach: When npm Trust Becomes an APT Attack Vector

A compromise of the Axios npm package introduced malicious versions 1.14.1 and 0.30.4 that added a covert dependency and executed a postinstall payload when developers or CI/CD systems installed the package. The excerpt attributes the activity to UNC1069, a North Korea-aligned cluster, citing overlap with WAVESHAPER.V2, infrastructure reuse, and operational similarities with earlier developer-ecosystem targeting. The infection chain used maintainer account takeover, direct npm publishing with a legacy token, obfuscated JavaScript, OS-specific second-stage payloads for macOS, Windows, and Linux, and C2 requests shaped to resemble npm registry traffic. The RAT beacons every 60 seconds with system metadata and supports command execution, payload staging, directory enumeration, and self-termination, while cleanup routines remove obvious traces within seconds. The incident matters because a short exposure window in a widely used dependency could still expose developer workstations, build pipelines, tokens, and downstream production systems.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 617b67a8e1210e4fc87c92d1d1da45a… 2026-03-30 2026-04-17
HASH 92ff08773995ebc8d55ec4b8e1a225d… 2026-03-30 2026-04-17
HASH fcb81618bb15edfdedfb638b4c08a2a… 2026-03-30 2026-04-17

Related Actors

Related Reports

« Back