AI & Enterprise
North Korean hackers hit Axios NPM package in supply-chain attack, millions distributed in 3 hours
North Korean hackers tampered with the Axios NPM package in a supply-chain attack that triggered millions of malicious distributions in about three hours, SecurityWeek reported. Google Threat Intelligence Group attributed the attack to UNC1069. Attackers posted backdoored Axios versions 1.14.1 and 0.30.4 to the NPM registry, designed to auto-run a malicious payload on Windows, macOS and Linux. The versions were later removed.