Skip to content

Axios

Disclosed Mar 31, 20265 months agoUnverified

Axios npm package hijacked to deliver cross-platform RAT

Attackers hijacked the npm and GitHub accounts of Axios's lead maintainer and published versions 1.14.1 and 0.30.4 with a dependency that installed remote access trojans on Windows, macOS and Linux. Google attributed the attack to North Korean group UNC1069; OpenAI later rotated macOS signing certificates after a workflow ran the malicious package.

What is known

People affectedNot stated in the sources we have
DisclosedMar 31, 2026
AttackSupply chain
Data exposedCredentials and tokens
SectorTech
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Notices filed

WhereFiledPeople
ResearchtotalMar 31
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about Axios

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.