#UNC1069
Email: Google links the Axios supply chain incident to UNC1069 (and not TeamPCP)
March 31, 2026 at 6:57 PM
"SEAL weekly stats: Sept. 15-22, 2026" published by SecurityAlliance. #UNC1069, #ContagiousInterview, #SINT01 https://radar.securityalliance.org/seal-weekly-stats-sept-15-22-2026
SEAL weekly stats: Sept. 15-22, 2026
radar.securityalliance.org
September 23, 2026 at 12:05 AM
We are still looking at the axios supply chain compromise, but we’ve attributed it to UNC1069, a suspected DPRK actor, who we covered in a blog this February. They are financially-motivated and historically DPRK uses these incidents to target crypto. cloud.google.com/blog/topics/...
UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering | Google Cloud Blog
North Korean threat actors target the cryptocurrency industry using AI-enabled social engineering such as deepfakes, and ClickFix.
cloud.google.com
March 31, 2026 at 7:48 PM
Google attributes the supply chain attack on HTTP client Axios to a suspected North Korean threat actor it calls UNC1069 (Lorenzo Franceschi-Bicchierai/TechCrunch)

Main Link | Techmeme Permalink
March 31, 2026 at 6:11 PM
Watch out as North Korean group #UNC1069 targets Node.js maintainers using fake LinkedIn and Slack profiles to spread malware and compromise open source packages.

Read: hackread.com/unc1069-node...

#CyberSecurity #NorthKorea #LinkedIn #Slack #Malware
UNC1069 Targets Node.js Maintainers via Fake LinkedIn, Slack Profiles
North Korean group UNC1069 targets Node.js maintainers using fake LinkedIn and Slack profiles to spread malware and compromise open source packages.
hackread.com
April 4, 2026 at 4:20 PM
Axios maintainer’s post mortem confirms social engineering by UNC1069
Axios maintainer’s post mortem confirms social engineering by UNC1069
View post on Reddit.
reddit.com
April 6, 2026 at 8:42 PM
UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack thehackernews.com/2026/04/unc1...
UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack
UNC1069 compromised Axios 1.14.1 and 0.30.4 via social engineering, impacting 100M weekly downloads and exposing supply chains.
thehackernews.com
April 5, 2026 at 9:19 AM
North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations
North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations
thehackernews.com
February 11, 2026 at 8:06 AM
Google is now linked the hack and hijack of the popular Axios npm open-source project to North Korea (UNC1069), which is known for stealing cryptocurrency.

Axios is downloaded tens of millions of times weekly, so this hack is likely widespread.

Our updated story: techcrunch.com/2026/03/31/h...
North Korean hackers blamed for hijacking popular Axios open-source project to spread malware | TechCrunch
A hacker inserted malware in Axios, an open-source web tool downloaded tens of millions of times weekly, in a widespread hack.
techcrunch.com
March 31, 2026 at 5:48 PM
GIGAZINE より

北朝鮮のハッカー「UNC1069」がオープンソースのAxiosに対するサプライチェーン攻撃の犯人だとGoogleが指摘
Google points out that North Korean hacker UNC1069 is the culprit of a supply chain attack on open sourcexios
北朝鮮のハッカー「UNC1069」がオープンソースのAxiosに対するサプライチェーン攻撃の犯人だとGoogleが指摘 - GIGAZINE Google points out North Korean hacker "UNC1069" is the culprit of supply chain attack on open sourcexios - GIGAZINE
JavaScriptライブラリ「Axios」がサプライチェーン攻撃を受けてリモートアクセス型トロイの木馬を仕込まれた件で、Googleのセキュリティ研究者が調査報告書を提出しました。Googleは、早くとも2018年から活動している北朝鮮関連の脅威アクター「UNC1069」が関与していると断定しています。
gigazine.net
April 2, 2026 at 5:19 PM
Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069 #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
April 1, 2026 at 8:17 AM
-South Korea warns of Midnight, Endpoint ransomware attacks
-North Korea is recruiting foreigners for its remote IT worker schemes
-Malware reports on Nexcorium IoT botnet, Black Shrantac and BravoX ransomware, BORZ C2, FaceFish rootkit, SHub Stealer
-UNC1069 goes back to spear-phishing
April 20, 2026 at 9:08 AM
"Axios npm Backdoored: UNC1069 Deploys Cross-Platform RAT via Supply Chain Attack" published by CybersecSentinel. #Axios, #NPM, #UNC1069, #DPRK, #CTI https://cybersecsentinel.com/axios-npm-backdoored-unc1069-deploys-cross-platform-rat-via-supply-chain-attack/
April 6, 2026 at 3:30 AM
Laut Sicherheitsforschern von Mandiant setzen nordkoreanische Hacker der Gruppe UNC1069 inzwischen hochentwickelte KI‑Tools, Deepfakes und Social Engineering ein, um gezielt Unternehmen der Finanz- und Kryptobranche anzugreifen. #CyberSecurity #Krypto #Deepfake #Cybercrime #Nordkorea #Hackerangriff
February 11, 2026 at 4:15 PM
UNC1069 Targets Node.js Maintainers via Fake LinkedIn, Slack Profiles

North Korean group UNC1069 targets Node.js maintainers using fake LinkedIn and Slack profiles to spread malware and compromise open source packages.
#hackernews #news
UNC1069 Targets Node.js Maintainers via Fake LinkedIn, Slack Profiles
North Korean group UNC1069 targets Node.js maintainers using fake LinkedIn and Slack profiles to spread malware and compromise open source packages.
hackread.com
April 6, 2026 at 12:24 AM
This is officially publicly attributed to Sapphire Sleet / BlueNoroff / TA444 / Stardust Chollima / DangerousPassword / UNC1069 / CageyChameleon. Yes, I know it’s a pile of ridiculous names and yes I know we, the CTI industry, created this mess. Sigh.

cloud.google.com/blog/topics/...
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack | Google Cloud Blog
A North Korea-nexus threat actor targeted the popular axios NPM package in a massive supply chain attack.
cloud.google.com
April 1, 2026 at 3:08 AM
North Korean group UNC1069 compromised the Axios npm package, deploying cross-platform malware via a sophisticated supply chain attack. Stay vigilant! #CyberSecurity #SupplyChainAttack #UNC1069 Link: thedailytechfeed.com/north-korean...
April 2, 2026 at 4:57 PM
Google links Axios npm supply chain attack to UNC1069 after trojanized versions 1.14.1 and 0.30.4 spread WAVESHAPER.V2, impacting multiple OS.
Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069
thehackernews.com
April 1, 2026 at 7:26 PM
North Korean hackers (UNC1069) are using AI & deepfakes to target crypto startups, per Google Cloud's Mandiant. They're deploying new malware via compromised Telegram accounts to steal data & assets. A serious threat to Web3. 🛡️ 💻 💰 #cryptonews #cybersecurity #AI #deepfakes
Cryptovka
CryptoMarket and Blockchain News
cryptovka.ru
February 11, 2026 at 12:25 PM