The North Korean threat actor behind the Axios supply chain attack has been targeting high-profile Node.js maintainers.
An emerging threat cluster is exploiting vulnerable Web-exposed Next.js apps and using an automated tool to steal credentials ...
North Korean hackers published backdoored versions of the Axios NPM package using a compromised long-lived access token.
On March 31, 2026, the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages ...