Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise
2026-07-31 • Google •
North Korean actor MIDNIGHT NEPTUNE, formerly UNC1069, used a socially compromised maintainer account to introduce a malicious dependency into `axios`, deploying the WAVESHAPER.V2 backdoor and potentially exposing a package ecosystem with more than 100 million weekly downloads. GTIG also cites UNC4899's compromise of a Web3 developer workstation, which enabled malicious frontend changes and approximately $1.4 billion in cryptocurrency theft. The broader assessment finds that open-source repository and dependency compromises expanded sharply during 2025 and early 2026, while traditional supply chain compromises remained rarer and more selectively targeted. Recommended defenses include package-release cooldowns, private registries, disabled lifecycle scripts, ephemeral CI/CD runners, short-lived credentials, provenance verification, and strict egress controls.