North Korean UNC1069 Hijacks Axios npm Package (100M Weekly Downloads) via Social Engineering — WAVESHAPER.V2 Backdoor Deployed
The Hacker News·high signal
On March 31, North Korean threat group UNC1069 compromised the Axios npm package maintainer through social engineering — cloning a legitimate company founder's likeness and creating a fake Slack workspace. They published malicious versions deploying the WAVESHAPER.V2 backdoor across Windows, macOS, and Linux. The malicious versions were live for ~3 hours and downloaded by roughly 3% of Axios's ~100M weekly userbase. Google Threat Intelligence Group publicly attributed the attack on April 1.