Midnight Neptune

2026-07-25 • GoogleBatten Down Your Packages: Mitigation Guidance fo…

Midnight Neptune is Google Threat Intelligence Group’s name for a North Korean actor formerly tracked as UNC1069. GTIG attributed the cluster to a March 2026 software supply-chain compromise involving the legitimate axios package. After social engineering compromised a maintainer account, the attacker introduced a malicious dependency that acted as a dropper for the WAVESHAPER.V2 backdoor. The affected versions remained available on npm for less than three hours, but the package’s enormous installation base and downstream dependency relationships created potentially broad exposure. GTIG assisted affected customers across at least fifteen industries and thirteen countries. The operation places Midnight Neptune within a growing pattern of North Korean activity targeting open-source repositories and software-development ecosystems, using trusted package relationships and compromised maintainers to distribute malicious code at scale rather than approaching every victim directly.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster