WAVESHAPER.V2 is a cross-platform remote access trojan and backdoor associated with UNC1069, a financially motivated North Korea-nexus threat actor active since at least 2018. It is assessed to be an updated evolution of the earlier WAVESHAPER malware family previously used by the same actor, including in operations targeting the cryptocurrency sector. Variants have been observed for macOS, Windows, and Linux, implemented respectively as native C++, PowerShell, and Python payloads.
WAVESHAPER.V2 has been used in software supply chain operations, most notably through poisoned npm package releases delivered via a malicious dependency that executed during package installation. In the observed campaign, the malware was distributed after a maintainer account takeover and deployed automatically on developer workstations, CI/CD systems, and other environments that installed the compromised package. This delivery chain provided broad downstream exposure because the targeted package was widely used directly and transitively.
The malware functions as a fully featured RAT. Its capabilities include host reconnaissance and system telemetry collection, such as user and host metadata, operating system details, boot time, time zone, and running process information. It supports file system and directory enumeration, arbitrary shell command execution, retrieval and execution of additional payloads, and on Windows specifically, in-memory Portable Executable injection. Reporting also indicates Windows persistence through logon autorun mechanisms. WAVESHAPER.V2 communicates with command-and-control infrastructure using JSON-based messaging and exhibits polling behavior shared with the earlier WAVESHAPER lineage.
The malware’s operational role is consistent with post-compromise access, reconnaissance, and follow-on intrusion enablement. In the broader campaign context, access obtained through WAVESHAPER.V2 created risk of credential theft from developer and build environments, downstream software supply chain compromise, SaaS and cloud compromise, extortion, ransomware enablement, and cryptocurrency theft. Attribution to UNC1069 is based on malware lineage, infrastructure overlap, and operational similarities with prior activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
At the time of writing, Google Threat Intelligence Group attributes this to UNC1069, a North Korea-nexus actor, based on the use of the WAVESHAPER.V2 backdoor and infrastructure overlaps with past UNC1069 activity.
These versions included a phantom dependency called "plain crypto js" that executed an obfuscated dropper during installation, deploying a cross platform Remote Access Trojan known as WAVESHAPER.V2 across Windows, macOS, and Linux systems.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Each wave used credentials stolen in a previous wave. Trivy tokens funded the npm wave. npm tokens funded LiteLLM. LiteLLM tokens funded Telnyx.
Between late February and March 2026, a threat actor known as TeamPCP conducted one of the most consequential software supply chain campaigns in recent memory... cascaded through some of the most widely trusted tools in cloud-native development — Trivy, Checkmarx KICS, LiteLLM, Telnyx, and dozens of npm packages.
These versions included a phantom dependency called "plain crypto js" that executed an obfuscated dropper during installation, deploying a cross platform Remote Access Trojan known as WAVESHAPER.V2 across Windows, macOS, and Linux systems.
capable of... command execution... and arbitrary shell commands
The shell execution command expects a script and script parameters from C2; if no script is provided, the parameter is executed as a PowerShell command...
Command Execution: Supports multiple execution methods, including in-memory Portable Executable (PE) injection and arbitrary shell commands.
macOS: Downloads a C++ Mach-O binary, stores it in /Library/Caches/com.apple.act.mond, and executes it via /bin/zsh.
Windows: Copies PowerShell to %PROGRAMDATA%\wt.exe, disguising it as Windows Terminal, and executes a secondary script via VBScript with registry-based persistence.
Linux: Retrieves a Python-based implant to /tmp/ld.py and executes it in the background using nohup.
capable of... command execution (in-memory Portable Executable injection and arbitrary shell commands)
a malicious dependency named "plain-crypto-js", an obfuscated dropper that deploys the WAVESHAPER.V2 backdoor
capable of... command execution (in-memory Portable Executable injection and arbitrary shell commands)
Within seconds of execution, the dropper deletes the setup script, removes the postinstall hook, and replaces modified package files with benign decoys.
Each wave used credentials stolen in a previous wave. Trivy tokens funded the npm wave. npm tokens funded LiteLLM. LiteLLM tokens funded Telnyx.
Reconnaissance: Extracts system telemetry, including hostname, username, boot time, time zone, OS version, and detailed running process lists.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cross-platform backdoor delivered via the malicious plain-crypto-js dependency in poisoned Axios package versions, capable of infecting Windows, macOS, and Linux systems.
A cross-platform remote access trojan deployed via an obfuscated dropper during the malicious Axios npm supply-chain compromise, affecting Windows, macOS, and Linux systems.
An implant distributed via a compromised Axios npm package following maintainer account takeover through social engineering.
A cross-platform remote access trojan framework delivered via a malicious Axios npm dependency. It supports persistence, reconnaissance, beaconing to C2 every 60 seconds, remote command execution, payload delivery, directory enumeration, and self-termination across macOS, Windows, and Linux.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.