#SILKBELL
North Korea phished an npm maintainer - axios itself shipped a cross-platform RAT. https://intel.threadlinqs.com/threat/TL-2026-1760 #ThreatIntel #WAVESHAPER #SILKBELL #SapphireSleet
July 29, 2026 at 9:52 PM
Two Axios npm releases were compromised for about three hours, injecting a malicious dependency that installed the WAVESHAPER RAT via a postinstall hook, impacting Windows and macOS systems. #UNC1069 #SupplyChain #USA
Examining the Blast Radius from the Axios npm Supply Chain Compromise
Two backdoored Axios npm releases ([email protected] and [email protected]) were published from a compromised maintainer account and, during a roughly three‑hour window, introduced a malicious dependency that installed a cross‑platform RAT via a postinstall hook. The campaign, attributed to UNC1069, deployed SILKBELL to fetch the WAVESHAPER RAT and led to detections across Windows and macOS with 19 affected eSentire customers; #WAVESHAPER #UNC1069
www.hendryadrian.com
April 11, 2026 at 8:00 PM
Supply-chain attacks hit npm with Axios trojan, Anthropic Claude Code leaks, LiteLLM breaches Mercor, and Cisco source code exposed via Trivy. Patches released for Chrome, Windows, GIGABYTE, TrueConf. #Romania #APT28 #SupplyChain
Cybersecurity News | Daily Recap [01 Apr 2026]
Daily Recap, the day’s headlines span supply‑chain compromises such as Axios trojanizing the npm package to drop SILKBELL and WAVESHAPER.V2, along with Anthropic Claude Code exposure, LiteLLM breaches affecting Mercor, and a Trivy‑related breach that exposed Cisco source code. Daily Recap, coverage also highlights AI/Cloud risks, CVEs and patches (Chrome CVE-2026-5281, Windows KB5086672, GIGABYTE CVE-2026-4415, TrueConf CVE-2026-3502) and editor RCEs for Vim/Emacs, plus nation‑state activity (APT28 PRISMEX, AgeWheeze, Handala Hack Team, Romania attacks), ransomware and crime trends (Meriden, Leak Bazaar, Uranium Theft) and policy shifts (FBI warning on Chinese apps, Proton Meet, Drive ransomware detection). #Axios #SILKBELL #WAVESHAPER #ClaudeCode #LiteLLM #Mercor #Trivy #Cisco #APT28 #PRISMEX #Romania #AgeWheeze #KashPatel #DutchTreasury #Meriden #LeakBazaar #Uranium #Vim #Emacs
www.hendryadrian.com
April 2, 2026 at 4:40 PM
North Korea-linked threat actor UNC1069 compromised the popular axios NPM package by injecting the plain-crypto-js dependency, deploying SILKBELL and WAVESHAPER.V2 malware across Windows, macOS, and Linux systems. #NorthKorea #SupplyChain #UNC1069
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack
Google Threat Intelligence Group (GTIG) observed a supply chain compromise of the axios NPM package where a malicious dependency, plain-crypto-js (v4.2.1), delivered an obfuscated dropper (SILKBELL) that installed WAVESHAPER.V2 across Windows, macOS, and Linux. GTIG attributes the campaign to UNC1069, details OS-specific deployment and persistence mechanisms, and recommends immediate remediation including pinning axios versions, auditing for plain-crypto-js, blocking sfrclak[.]com/142.11.206.73, and rotating credentials. #WAVESHAPER.V2 #UNC1069
www.hendryadrian.com
April 2, 2026 at 3:20 AM
Google links the Axios npm supply chain attack to North Korea’s UNC1069 group. Trojanized Axios versions added “plain-crypto-js,” deploying SILKBELL dropper and WAVESHAPER.V2 backdoor via postinstall hook. #UNC1069 #NorthKorea #SupplyChain
Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069
Google has attributed the supply chain compromise of the popular Axios npm package to a financially motivated North Korean cluster tracked as UNC1069. The attackers pushed trojanized Axios releases that installed a malicious dependency "plain-crypto-js" which deployed the SILKBELL dropper and the cross-platform WAVESHAPER.V2 backdoor. #UNC1069 #WAVESHAPERV2...
www.hendryadrian.com
April 1, 2026 at 11:00 AM
North Korea’s Lazarus Group compromised Axios npm releases on March 31 by inserting a malicious dependency plain-crypto-js with a postinstall hook deploying the SILKBELL dropper and WAVESHAPER.V2 backdoor. #NorthKorea #SupplyChain #LazarusGroup
North Korea’s Lazarus Group Behind the Axios npm Supply Chain Attack
A supply chain attack inserted a malicious dependency, plain-crypto-js, into axios npm releases (1.14.1 and 0.30.4) on March 31, using a postinstall hook that executed an obfuscated dropper (tracked as SILKBELL) to deploy platform-specific payloads. Multiple threat intelligence firms (GTIG, Mandiant, ThreatBook) attributed the campaign to North Korea’s Lazarus Group/UNC1069, which...
www.hendryadrian.com
April 1, 2026 at 8:20 AM
North Korea’s Lazarus Group Strikes Again: Malicious NPM Package Compromises Axios Releases

Cybersecurity experts are raising alarms after North Korea’s notorious Lazarus Group infiltrated the widely used Axios npm library, highlighting ongoing risks in the software supply chain. On March 31,…
North Korea’s Lazarus Group Strikes Again: Malicious NPM Package Compromises Axios Releases
Cybersecurity experts are raising alarms after North Korea’s notorious Lazarus Group infiltrated the widely used Axios npm library, highlighting ongoing risks in the software supply chain. On March 31, 2026, Lazarus operatives inserted a malicious dependency called plain-crypto-js into Axios releases. This dependency contained a post-install hook that deployed the SILKBELL dropper and the WAVESHAPER.V2 backdoor, potentially allowing hackers to compromise systems silently.
undercodenews.com
April 1, 2026 at 9:03 AM
Axios NPM Supply Chain Attack: UNC1069’s SILKBELL Dropper Unleashes WAVESHAPERV2 RAT on Global Development Environments + Video

Introduction: The software supply chain has become the most coveted battleground for advanced threat actors, with open-source repositories serving as the perfect vector…
Axios NPM Supply Chain Attack: UNC1069’s SILKBELL Dropper Unleashes WAVESHAPERV2 RAT on Global Development Environments + Video
Introduction: The software supply chain has become the most coveted battleground for advanced threat actors, with open-source repositories serving as the perfect vector for mass compromise. In a critical alert issued by Mandiant (part of Google Cloud), the widely trusted Node Package Manager (NPM) library axios—which averages over 100 million weekly downloads—has been backdoored in versions 1.14.1 and 0.30.4. This attack, attributed to the North Korea-nexus threat actor UNC1069, leverages a malicious dependency named "plain-crypto-js" to deploy a sophisticated cross-platform backdoor, marking a severe escalation in supply chain risk for enterprise development pipelines.
undercodetesting.com
April 2, 2026 at 2:18 AM