Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

The axios breach shows how fragile the npm supply chain remains

Google Threat Intelligence Group said the malicious dependency acted as an obfuscated dropper that installed Waveshaper.v2, a backdoor capable of running on Windows, Linux, and Mac systems.

byAytun Çelebi
April 2, 2026
in Research
Home Research
Share on FacebookShare on TwitterShare on LinkedInShare on WhatsAppShare on e-mail
Google Preferred Source

A supply chain attack targeting the axios JavaScript library, which sees over 100 million downloads weekly, is attributed to a North Korean threat actor, according to security researchers.

Compromised this week, the npm account of an axios maintainer led to the introduction of a malicious dependency named plain-crypto-js. Although the malicious versions were removed within hours, the risk remains that many users downloaded the compromised version due to axios’s extensive usage.

Google Threat Intelligence Group researchers identified the malicious dependency as an obfuscated dropper that installs a backdoor called Waveshaper.v2 across Windows, Linux, and Mac systems. The attacker, tracked as UNC1069, has been active since at least 2018, with the newly discovered backdoor being an updated variant previously linked to this group.

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

Sophos researchers connected the attack to a North Korean hacking group known as Nickel Gladstone. “North Korean hackers have deep experience with supply chain attacks, which they’ve historically used to steal cryptocurrency,” said John Hultquist, chief analyst at GTIG. He added that the overall impact of this incident is still unknown but is expected to be significant.

Austin Larsen, principal threat analyst at GTIG, cautioned that users who downloaded axios versions 1.14.1 and 1.30.4 may have inadvertently executed a backdoor payload linked to the malicious dependency. According to a post on LinkedIn, the initial attack activity was staged 18 hours prior to deployment.

Step Security, which detected the attack, stated that the payloads were intentionally prepared for deployment across three operating systems. “Both release branches were poisoned within 39 minutes of each other,” researchers noted. The attacker compromised the npm account of maintainer jasonsaayman, changing the registered email to one controlled by the threat actor.

This malicious artifact was designed to self-destruct after execution. Research teams characterized the attack as one of the “most operationally sophisticated supply chain attacks ever documented” against a major npm package.

John Hammond, senior principal security researcher at Huntress, warned of potential downstream effects for organizations utilizing Node.js or JavaScript-based software relying on the axios component. “Unfortunately, the full effects are dynamic and still being uncovered,” Hammond stated, indicating the widespread implications for various software environments.

The axios compromise is part of a worrying trend of supply chain attacks, with another recent incident involving Trivy, an open-source tool from Aqua Security, linked to a threat actor identified as TeamPCB. Charles Carmakal, CTO at Mandiant Consulting, revealed that thousands of stolen credentials have emerged as a result of these recent supply chain breaches, warning of possible future compromises, ransomware, and crypto thefts.


Featured image credit

Tags: axiosGoogle

Related Posts

Adobe report finds 86% of creators now use generative AI in workflows

Adobe report finds 86% of creators now use generative AI in workflows

June 17, 2026
AI transfer learning speeds cosmology research but has hidden risks

AI transfer learning speeds cosmology research but has hidden risks

June 15, 2026
Phishing scams targeting travelers hit record levels in 2026

Phishing scams targeting travelers hit record levels in 2026

June 15, 2026
Most UK SMEs now consult AI before their accountants

Most UK SMEs now consult AI before their accountants

June 12, 2026
Faith in large employers is fading among UK workers

Faith in large employers is fading among UK workers

June 5, 2026
Army-funded scientists explore a new frontier in quantum physics

Army-funded scientists explore a new frontier in quantum physics

June 5, 2026

LATEST NEWS

Steam Next Fest sees one in five demos labeled for generative AI

Qualcomm debuts Snapdragon Reality Elite chip for AR and VR devices

Roblox expands age-based account tiers worldwide with new parental controls

Anthropic adds multilingual and push-to-talk features to Claude Voice Mode

Is Gemini down? Users report problems with Google Gemini

Google releases Android 17

BEST AI MODELS LEADERBOARD

See the best AI models, ranked by intelligence, benchmark results, speed and token price. Find the most suitable LLMs, Text-to-Image, Image Editing, Text-to-Speech, Text-to-Video and Image-to-Video  artificial intelligence model for your tasks and business.

LATEST TOOLS

Wiz Write

BoldVoice

Bith

Concisely

YourGPT

Sonoteller

RoomGPT

Rosie

LedgerUp

Call Annie

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI tools
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies to improve your experience. You can choose to accept or reject them. Visit our Privacy Policy.