HomeSecurityUNC1069 attack on Axios npm package with social engineering

UNC1069 attack on Axios npm package with social engineering

The UNC1069 group from North Korea has carried out a sophisticated social engineering attack against the maintainer of the popular Axios npm package , leading to one of the most significant supply chain attacks in recent years. Jason Saayman , the project’s maintainer, confirmed that the attackers used highly targeted social engineering techniques to gain access to the npm account . This attack highlights the growing threat that open-source project maintainers face from state-sponsored hackers seeking to exploit the trust in the software ecosystem.

See also: Google attributes Axios Supply Chain Attack to UNC1069

UNC1069

Axios , one of the most popular JavaScript HTTP clients with over 100 million weekly downloads , was targeted on March 31, 2026 between 00:21 and 03:20 UTC . The attackers released two malicious versions of the package: 1.14.1 (tagged as “latest”) and 0.30.4 (tagged as “legacy”), which contained the WAVESHAPER.V2 malware . The choice of Axios as a target was not accidental – the package is used in about 80% of cloud environments and is a critical dependency for thousands of other projects, making it ideal for attacks with a large blast radius.

According to Saayman, the attackers initially approached him by impersonating the founder of a legitimate and well-known company. “They had cloned the appearance of the company’s founders as well as the company itself,” the maintainer explained. The attackers created a fully functional Slack workspace with the company’s branding, including channels where they shared posts from LinkedIn. This level of detail in the preparation of the attack reveals the extensive reconnaissance that UNC1069, as well as the significant resources it allocated to this campaign.

Technical Details of the UNC1069 Attack

The attack unfolded when threat actors scheduled a meeting with Saayman via Microsoft Teams. During the fake call, he was presented with a fake error message claiming that “something on his system was out of date.” Once the update was activated, a remote access trojan to his system. This tactic is typical of North Korean groups, which often use fake software updates or security warnings to mislead their victims.

The Trojan gave the attackers access to Saayman 's npm account credentials . The hackers changed the account's email to ifstap@proton.me and used a long-term NPM_TOKEN to publish directly via the npm CLI , bypassing the OIDC (OpenID Connect) trusted publishing workflow that was tied to GitHub Actions . This highlights a critical weakness in npm 's security system , where long-term tokens can be used as a fallback mechanism, even when more secure authentication systems have been implemented.

See also: Axios Supply Chain Attack: Malicious versions distribute RAT

UNC1069 attack on Axios npm package with social engineering

The Google Threat Intelligence Group (GTIG) attributed the attack with high confidence to the UNC1069, based on overlaps with the WAVESHAPER.V2, reuse of the C2 infrastructure (sfrclak[.]com at 142.11.206.73 via an AstrillVPN node), and tactics such as credential theft for espionage and financial gain. UNC1069 is known for targeting cryptocurrency founders, VCs, and other high-profile targets, but this shift to targeting open-source maintainers represents a worrying escalation in its tactics.

Impact and Detection of the Attack

Huntress detected 135 endpoints (on macOS , Windows , Linux ) communicating with the C2 infrastructure during the three-hour exposure window. The broad reach of Axios – present in approximately 80% of cloud environments – significantly amplified the impact of the attack. Organizations that installed the affected versions during the exposure window should consider their systems fully compromised.

The malicious versions contained a dependency named “plain-crypto-js” that executed a post-install script to download the WAVESHAPER.V2 RAT via a multi-stage SILKBELL dropper. The malware targeted credentials and used the C2 path “/6202033” (reversed attack date 3-30-2026) as a UNC1069. WAVESHAPER.V2 is an updated version of the known C++ backdoor that supports multiple platforms and has the ability to steal credentials, SSH keys, and Kubernetes tokens.

The attackers horizontally extended the attack via the @shadanai/openclaw and @qqbrowser/openclaw-qbot, which contained malicious versions of Axios. Elastic Security Labs first flagged the links to UNC1069 via functionality overlaps, while Thrivenextgen flagged the features of the SILKBELL dropper. This secondary infection demonstrates the attackers’ attempt to extend their influence and maintain access even after the initial malicious packages were removed.

Safety Precautions and Recommendations

As preventative measures, Saayman outlined several changes, including resetting all devices and credentials, installing immutable releases, adopting OIDC flow for publishing, and updating GitHub Actions to adopt best practices. Experts recommend immediately removing affected releases, replacing all long-term npm tokens, and implementing multi-factor authentication (MFA) on npm and GitHub accounts.

See also: Social Engineering: The most dangerous “human” virus

UNC1069 attack on Axios npm package with social engineering

Additionally, organizations should implement monitoring systems for anomalous package releases, use package provenance verification through tools like sigstore, and conduct regular social engineering for maintainers of critical projects. Tenable and StepSecurity highlighted the need for stricter management of NPM_TOKENs and the elimination of fallback mechanisms that allow bypassing of modern security systems.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS