Mark RadarMARK RADAR
EN

North Korean Hackers Target npm Package Axios in Supply-Chain Attack, Use AI to Sharpen Social Engineering

2 reports · First detected 2026-04-01 · Last active 2026-04-30

Axios is a widely used npm package for making HTTP requests. If its release process or a maintainer’s account is compromised, malicious code could spread through updates to numerous downstream projects. Google attributed the attack to North Korean hacking group UNC1069, which sought to deploy the WaveShaper.V2 remote-access trojan and generate illicit financial gains. The amount involved has not been disclosed.

Google’s latest investigation found that UNC1069 not only used Axios to mount a supply-chain attack but also began using AI-generated content to strengthen its social-engineering tactics. The approach made it more efficient at deceiving developers and stealing credentials. A separate npm attack called Mini Shai-Hulud targeted several SAP packages on April 30, highlighting the continuing risk that credentials and release pipelines will be abused across the open-source package ecosystem.

All Coverage

2 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR