Pull to refresh
Logo
Daily Brief
Following
Why Sign Up
npm (GitHub/Microsoft)

npm (GitHub/Microsoft)

Package registry

Appears in 1 story

Stories

North Korean hackers compromise Axios, one of the most-used packages in the npm ecosystem

Force in Play

Removed malicious packages; investigating security gaps

Axios is installed in roughly 80% of cloud and code environments and downloaded over 100 million times per week. On March 31, 2026, a North Korean hacking group hijacked the npm account of its lead maintainer, published two backdoored versions containing a cross-platform remote access trojan, and had them live for nearly three hours before anyone noticed. Google's Threat Intelligence Group formally attributed the attack to UNC1069, a financially motivated North Korean threat cluster active since at least 2018.

Updated 3 hours ago