UNC1069 Axios npm supply-chain campaign targeting build pipelines
Campaign
Summary
Hide ▲
Show ▼
The Axios npm supply-chain compromise has been tied to UNC1069, putting npm consumers and downstream build pipelines at risk from trojanized releases. Attackers seized the maintainer's account and pushed malicious 1.14.1 and 0.30.4 versions that inserted plain-crypto-js. The delivery chain used a postinstall hook and a SILKBELL dropper to stage payloads for Windows, macOS, and Linux. The operation's reach and multi-platform design make it a reusable template for software supply-chain abuse rather than a one-off package issue.
Related Happenings
AsyncAPI malicious npm package supply-chain malware
Malware Activity
H score21
First: 15.07.2026 18:37
Last: 15.07.2026 18:37
Sources 1
About this happening:
Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...
AsyncAPI malicious npm package supply-chain malware
Malware ActivityAbout this happening: Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...
Compromised @asyncapi npm packages distributing the Miasma loader
Malware Activity
H score29
First: 15.07.2026 12:16
Last: 15.07.2026 12:16
Sources 1
About this happening:
Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....
Compromised @asyncapi npm packages distributing the Miasma loader
Malware ActivityAbout this happening: Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....
@Injectivelabs/[email protected] wallet-stealing package
Malware Activity
H score30
First: 10.07.2026 20:29
Last: 10.07.2026 20:29
Sources 1
About this happening:
The malicious @injectivelabs/[email protected] package is a wallet-stealing malware activity that can expose private keys and mnemonic seed phrases when library functions...
@Injectivelabs/[email protected] wallet-stealing package
Malware ActivityAbout this happening: The malicious @injectivelabs/[email protected] package is a wallet-stealing malware activity that can expose private keys and mnemonic seed phrases when library functions...
Malicious npm and PyPI Paysafe, Skrill, and Neteller SDK packages delivering stealer malware
Malware Activity
H score37
First: 08.07.2026 22:54
Last: 08.07.2026 22:54
Sources 1
About this happening:
Malicious npm and PyPI packages impersonating Paysafe, Skrill, and Neteller SDKs delivered stealer malware that siphoned secrets from developer environment...
Malicious npm and PyPI Paysafe, Skrill, and Neteller SDK packages delivering stealer malware
Malware ActivityAbout this happening: Malicious npm and PyPI packages impersonating Paysafe, Skrill, and Neteller SDKs delivered stealer malware that siphoned secrets from developer environment...
Rollup polyfill npm package malware activity for remote access and data theft
Malware Activity
H score16
First: 03.07.2026 19:07
Last: 03.07.2026 19:07
Sources 1
About this happening:
Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...
Rollup polyfill npm package malware activity for remote access and data theft
Malware ActivityAbout this happening: Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...
Timeline
-
13.04.2026 20:39 1 articles · 3mo ago
OpenAI rotates macOS code-signing certificates after Axios attack
Mitigation Patch UpdateOpenAI is revoking and rotating potentially exposed macOS code-signing certificates after a GitHub Actions workflow executed a compromised Axios package version 1.14.1 during a March 31, 2026 supply-chain attack. The workflow had access to certificates used to sign ChatGPT Desktop, Codex, Codex CLI, and Atlas, and OpenAI says it found no evidence that user data, systems, intellectual property, or the signing certificate were compromised.
Show sources
- OpenAI rotates macOS certs after Axios attack hit code-signing workflow — www.bleepingcomputer.com — 13.04.2026 20:39
-
01.04.2026 10:44 1 articles · 3mo ago
Google attributes Axios npm supply-chain compromise to UNC1069
Initial DisclosureGoogle attributed the Axios npm package supply-chain compromise to UNC1069, a suspected North Korean threat cluster, after attackers hijacked the maintainer's npm account and pushed trojanized 1.14.1 and 0.30.4 releases that added plain-crypto-js and enabled SILKBELL and WAVESHAPER.V2 payload delivery for Windows, macOS, and Linux systems.
Show sources
- Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069 — thehackernews.com — 01.04.2026 10:44