A suspected North Korean threat actor compromised a maintainer account for the widely used open-source package Axios and pushed malicious updates for about three hours in a software supply-chain attack, according to reporting from CNN, NK News, and security researchers cited by both outlets. Google Threat Intelligence Group and Mandiant linked the operation to North Korean actors, saying the attackers likely sought information to support follow-on intrusions and cryptocurrency theft. Axios is broadly embedded in web applications and server-to-server communications, raising concern that the compromise could affect organizations across healthcare, finance, and cryptocurrency-related sectors.
Incident responders said the known impact was still developing, with Huntress identifying roughly 135 compromised devices across about 12 companies while warning the downstream victim count could grow substantially because Axios is used by thousands of enterprises. Researchers said the campaign fits Pyongyang’s established pattern of using cyber operations for revenue generation and strategic access, and warned that determining the full scope of exposure and any secondary compromises could take months.
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Google Threat Intelligence Group disclosed the Axios compromise the day after the breach was reported to have occurred, and Mandiant attributed the activity to a suspected North Korean group. Huntress said it had identified about 135 compromised devices across roughly 12 companies, with the potential impact expected to grow because Axios is widely used.
A suspected North Korean threat actor compromised the account of a maintainer of the open-source Axios package and used it for about three hours to distribute malicious updates. The operation was assessed as a software supply-chain attack likely intended to support future intrusions and cryptocurrency theft.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
nknews.org
Open sourcecnn.com
Open sourcereverse.put.as
Open sourcephrack.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.