- Updated: March 31, 2026
- 1 min read
North Korean Hackers Hijack Axios Library in Massive Supply‑Chain Attack
In a striking supply‑chain breach, a suspected North‑Korean threat actor (identified as UNC1069) compromised the maintainer’s account of the widely‑used Axios JavaScript library on npm. By publishing a malicious version of the package, the attackers injected a self‑deleting remote access trojan that silently infected developers who installed the compromised release. The malicious code was live for roughly three hours, potentially affecting millions of projects that depend on Axios.
The breach was first uncovered by StepSecurity, which quickly alerted npm, Google, and the broader security community. npm removed the tainted version and reinstated the original package, while Google flagged the compromised code in its Safe Browsing system. Developers are urged to update to the latest clean version of Axios, audit their dependencies, and rotate any credentials that may have been exposed.
For a deeper dive into the incident, see our Supply‑Chain Security guide and the NPM Security Best Practices article. The full TechCrunch report can be read here.
Andrii Bidochko
CTO UBOS
Andrii Bidochko is an AI entrepreneur and researcher focused on AI agents, reinforcement learning, and autonomous systems. He writes about the technologies shaping the future of machine intelligence, from frontier models and agent architectures to real-world AI applications.