Find notable cyber news and cases, enriched with sources, timelines, and signals.

UNC1069 Axios npm supply-chain campaign targeting build pipelines

Campaign
First reported
Last updated
Happening score
H score 45
2 unique sources, 2 articles

Summary

Hide ▲

The Axios npm supply-chain compromise has been tied to UNC1069, putting npm consumers and downstream build pipelines at risk from trojanized releases. Attackers seized the maintainer's account and pushed malicious 1.14.1 and 0.30.4 versions that inserted plain-crypto-js. The delivery chain used a postinstall hook and a SILKBELL dropper to stage payloads for Windows, macOS, and Linux. The operation's reach and multi-platform design make it a reusable template for software supply-chain abuse rather than a one-off package issue.

Related Happenings

AsyncAPI malicious npm package supply-chain malware

Malware Activity
H score21 First: 15.07.2026 18:37 Last: 15.07.2026 18:37 Sources 1

About this happening: Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...

Compromised @asyncapi npm packages distributing the Miasma loader

Malware Activity
H score29 First: 15.07.2026 12:16 Last: 15.07.2026 12:16 Sources 1

About this happening: Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....

@Injectivelabs/[email protected] wallet-stealing package

Malware Activity
H score30 First: 10.07.2026 20:29 Last: 10.07.2026 20:29 Sources 1

About this happening: The malicious @injectivelabs/[email protected] package is a wallet-stealing malware activity that can expose private keys and mnemonic seed phrases when library functions...

Malicious npm and PyPI Paysafe, Skrill, and Neteller SDK packages delivering stealer malware

Malware Activity
H score37 First: 08.07.2026 22:54 Last: 08.07.2026 22:54 Sources 1

About this happening: Malicious npm and PyPI packages impersonating Paysafe, Skrill, and Neteller SDKs delivered stealer malware that siphoned secrets from developer environment...

Rollup polyfill npm package malware activity for remote access and data theft

Malware Activity
H score16 First: 03.07.2026 19:07 Last: 03.07.2026 19:07 Sources 1

About this happening: Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...

Timeline

  1. 13.04.2026 20:39 1 articles · 3mo ago

    OpenAI rotates macOS code-signing certificates after Axios attack

    Mitigation Patch Update

    OpenAI is revoking and rotating potentially exposed macOS code-signing certificates after a GitHub Actions workflow executed a compromised Axios package version 1.14.1 during a March 31, 2026 supply-chain attack. The workflow had access to certificates used to sign ChatGPT Desktop, Codex, Codex CLI, and Atlas, and OpenAI says it found no evidence that user data, systems, intellectual property, or the signing certificate were compromised.

    Show sources
  2. 01.04.2026 10:44 1 articles · 3mo ago

    Google attributes Axios npm supply-chain compromise to UNC1069

    Initial Disclosure

    Google attributed the Axios npm package supply-chain compromise to UNC1069, a suspected North Korean threat cluster, after attackers hijacked the maintainer's npm account and pushed trojanized 1.14.1 and 0.30.4 releases that added plain-crypto-js and enabled SILKBELL and WAVESHAPER.V2 payload delivery for Windows, macOS, and Linux systems.

    Show sources