Security researchers at Kaspersky have uncovered technical evidence linking the massive supply chain attack on the popular ...
The cloud computing giant said in a blog post on July 29 that compromises of the axios, debug, chalk and typo-crypto libraries were carried out by the same group, known as Saphire Sleet, BlueNoroff ...
AWS Links Npm Attacks To North Korean Hackers Arabian Post. clearfix>Amazon Web Services has attributed a series of compromises involving widely used npm software packages, including Axios, Debug and ...
Amazon threat researchers found one threat actor behind four distinct open source compromises, including the March 2026 ...
Amazon Threat Intelligence has tied a DPRK hacking group to four separate NPM package supply chain attacks, including axios. The company’s security teams have connected the axios, debug, chalk, and ...
New findings connect the same Pyongyang-backed group to four compromises dating to 2025, revealing a larger operation than ...
The malicious dependency used an npm “postinstall” command, which automatically runs code when a package is installed. Its obfuscated downloader identified the victim’s operating system and deployed a ...
A slew of attacks against open-source libraries trace back to a financially motivated North Korean nation-state threat actor, finds analysis from Amazon Web Services set for publication Wednesday ...
Fireship on MSN
The silent threat: Axios library exposes developers
A recently discovered Remote Access Trojan in the widely used Axios library puts millions of JavaScript developers at risk. The sophisticated hack, masked as a legitimate update, allows malicious ...
North Korea-Nexus Threat Actor Compromised popular NPM package Axios with over 100 million weekly downloads A financially motivated North Korean hacking group compromised an NPM package Axios, with ...
A suspected North Korean hacker has hijacked and modified a popular open source software development tool to deliver malware that could put millions of developers at risk of being compromised. On ...
The widely used Axios HTTP client library, a JavaScript component used by developers, was recently hacked to distribute malware via a compromised account. Attackers exploited a hijacked account on npm ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results