The npm package express-session-js typosquatted the legitimate express-session middleware and executed malicious code as a side effect of require(), rather than through an install hook. Its dropper retrieved an obfuscated stage-two payload from jsonkeeper…
« Reports in 2026
593 reports
Flare Research found evidence that North Korean IT worker operators are recruiting people from Iran, Syria, Lebanon, Saudi Arabia, and other countries to support remote employment fraud against Western organizations. Internal documents described facilitat…
Elastic described detecting malicious axios npm releases through a monitoring pipeline that downloaded new package versions, diffed them against prior releases, and used an LLM to flag high-confidence supply-chain compromise. The malicious axios versions …
Veracode found that [email protected] and [email protected] were published after an npm account compromise, with the only Axios change being the addition of plain-crypto-js as a dependency. That dependency was never imported by Axios and existed to run a postinstal…
FortiGuard Labs observed DPRK-related LNK phishing campaigns targeting users in South Korea and other Korean companies through multi-stage PowerShell and VBScript execution on Windows. Earlier variants exposed metadata and GitHub command-and-control detai…
Two malicious Axios releases briefly published to npm introduced a dependency that installed a remote access trojan across macOS, Windows, and Linux. Axios maintainer Jason Saayman said the compromise began with a targeted social engineering operation in …
Two malicious Axios versions, 1.14.1 and 0.30.4, were published to npm on March 31, 2026 after the lead maintainer's account was compromised. The attacker injected [email protected], which installed a remote access trojan on macOS, Windows, and Linux …
Elliptic identified multiple indicators suggesting the $286 million Drift Protocol exploit may be linked to DPRK activity, citing on-chain behavior, laundering methods, and network-level indicators consistent with previous DPRK-attributed operations. The …
A malicious actor gained unauthorized administrative control over Drift Protocol by abusing durable nonce accounts and previously obtained multisig approvals. The intrusion was not attributed to a smart-contract flaw or compromised seed phrases; the excer…
Breakglass maps a DPRK Contagious Interview campaign in which North Korean operators pose as recruiters and lure software developers into running ClickFix-style setup commands during fake job interviews. The observed chain uses BeaverTail and InvisibleFer…
360 attributes the Axios npm supply-chain compromise to Lazarus with strong confidence, citing overlaps with GhostCall activity and RustBucket-related macOS components. Attackers hijacked the axios maintainer account and published malicious [email protected] a…
Bitdefender attributes the axios incident to an unknown threat actor, not to any named state group, and describes a supply-chain compromise of the primary maintainer's npm account. The attacker published [email protected] and [email protected] with a hidden plain-c…
SECUI STIC analyzes an Axios supply-chain compromise in which attackers stole maintainer credentials and altered npm installation behavior so a malicious setup.js loader ran automatically when affected packages were installed. The loader used custom obfus…
Malicious Axios npm releases 1.14.1 and 0.30.4 allegedly used a compromised maintainer account to add the hidden [email protected] dependency, causing npm install to execute a postinstall dropper. The excerpt attributes the operation to UNC1069, descr…
Unit 42 reports that compromised Axios npm releases v1.14.1 and v0.30.4 added a hidden dependency, plain-crypto-js, which executed a postinstall dropper and deployed cross-platform RAT payloads on macOS, Windows, and Linux. The infection chain used obfusc…