HomeSecurityGoogle Attributes Axios Supply Chain Attack to UNC1069

Google attributes Axios Supply Chain Attack to UNC1069

Google has linked the supply chain attack on the Axios npm package to the North Korean group UNC1069 , a financially motivated threat group that has been active since 2018. The attack targeted millions of developers worldwide, as Axios is very popular and receives many downloads every week. This attack is one of the most serious supply chain compromises ever recorded in the npm ecosystem , with potential impacts spanning thousands of applications and services.

UNC1069 Axios npm Supply Chain

According to John Hultquist, chief analyst at Google Threat Intelligence Group (GTIG), supply chain attacks are a specialty of North Korean hackers, who have historically used them to steal cryptocurrencies and fund state activities.

“The full extent of this incident remains unclear, but given the popularity of the compromised package, we expect it to have widespread implications,” he told The Hacker News.

See also: Axios Supply Chain Attack: Malicious versions distribute RAT

UNC1069 on cryptocurrency companies and decentralized finance platforms, making it one of the most active and dangerous groups in cyberspace.

The threat actors managed to gain control of the package maintainer's npm account . This allowed them to bypass GitHub Actions CI/CD protections and directly publish two trojanized versions – 1.14.1 and 0.30.4 – to the npm registry . These versions contained a malicious dependency named “plain-crypto-js” , which was used to deliver a cross-platform backdoor capable of infecting Windows , macOS , and Linux systems .

The attack did not introduce code changes to Axios itself , but leveraged a postinstall hook within the malicious dependency’s “package.json” file to achieve stealth execution. Once the compromised Axios package is installed, npm automatically triggers the execution of malicious code in the background , with the entire process taking about 15 seconds . This technique is particularly insidious as it exploits the automatic operation of the npm package manager and requires no action from the developer beyond the normal installation of the package.

Axios npm supply chain attack by the UNC1069 team

Technical details of the Axios and WAVESHAPER.V2 attack

The “plain-crypto-js” package acts as a “payload delivery vehicle” for an obfuscated JavaScript dropper codenamed SILKBELL (“setup.js”), which retrieves the next stage from a remote server based on the victim’s operating system. On Windows systems it delivers a PowerShell malware, on macOS a C++ Mach-O binary , and on Linux a Python backdoor.

After installation, the dropper performs cleanup procedures to remove itself and replace the “package.json” file of the “plain-crypto-js” package with a clean version that does not contain the postinstall hook, making detection extremely difficult.

See also: New malicious packages revealed in NuGet Supply Chain Attack

The backdoor, codenamed WAVESHAPER.V2, is assessed as an updated version of WAVESHAPER, a C++ backdoor developed by UNC1069 for attacks in the cryptocurrency sector.

The three variants of WAVESHAPER.V2 support four different commands while sending signals to the command-and-control (C2) server at 60-second.

The commands include:

  • kill to terminate the execution of the malware,
  • rundir for listing directory listings along with file paths and timestamps,
  • runscript for executing AppleScript, PowerShell or shell commands and
  • peinject, for decoding and executing arbitrary binaries.

According to Mandiant and GTIG, WAVESHAPER.V2 is a direct evolution of WAVESHAPER. While the original version used a lightweight, raw binary C2 protocol and implemented code packing, WAVESHAPER.V2 communicates using JSON, collects additional system information, and supports more backdoor commands. Despite the upgrades, both versions accept the C2 URL dynamically via command-line arguments and share identical polling behaviors and an unusual User-Agent string.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Google attributes Axios Supply Chain Attack to UNC1069

Protection strategies

To address the threat, users are advised to perform an extensive audit of their dependency trees for compromised versions and downgrade to a safe version. They should also pin Axios to a known safe version in the “package-lock.json” file, check for the presence of “plain-crypto-js” in “node_modules,” and terminate malicious processes.

See also: Open VSX: Supply Chain attack distributes GlassWorm via compromised dev account

Organizations should implement supply chain security tools that scan for malicious dependencies and unusual package behavior, as well as enable two-factor authentication on npm accounts.

Organizations should also block the C2 domain (“sfrclak[.]com”, IP address: 142.11.206[.]73), isolate affected systems, and change all credentials. The Axios should be understood as a template rather than an isolated event, as the methods used indicate a significant threat.

Additionally, organizations should install CI/CD pipeline protections beyond basic GitHub Actions to prevent unauthorized package publication and monitor for indicators of compromise.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS