Axios
Disclosed Mar 31, 20265 months agoUnverified
Axios npm package hijacked to deliver cross-platform RAT
Attackers hijacked the npm and GitHub accounts of Axios's lead maintainer and published versions 1.14.1 and 0.30.4 with a dependency that installed remote access trojans on Windows, macOS and Linux. Google attributed the attack to North Korean group UNC1069; OpenAI later rotated macOS signing certificates after a workflow ran the malicious package.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Mar 31, 2026 |
| Attack | Supply chain |
| Data exposed | Credentials and tokens |
| Sector | Tech |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| Hackers compromise Axios npm package to drop cross-platform malwarebleepingcomputer.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Mar 31 |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.