Signal

North Korean-linked supply chain attack compromises Axios npm packages

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-04-01 18:30 UTCUpdated 2026-04-02 15:16 UTC
rss
cveexploitsmalwarethreat_actorssecurity_toolingincident_response
Source links open
Source links and full evidence are open here. Pro adds archive history, compare-over-time, alerts, exports, and workflow. Business adds Feed API integrations and team usage.
No card needed for the free brief.
Evidence trail (top sources)
top sources (3 domains)domains are deduped. counts indicate coverage, not truth.
3 top sources shown
Overview

On March 31, 2026, malicious versions of Axios, a widely used npm package, were discovered containing a backdoor linked to North Korean state actor Sapphire Sleet.

Entities
AxiosMicrosoftGoogleSapphire Sleet
Score total
1.27
Momentum 24h
3
Evidence documents
-
Independent publishers
-
Independent origins
-
Primary sources
-
Secondary sources
-
Source types
-
Duplicate ratio
0%
Why now
  • The Axios compromise was discovered on March 31, 2026, making it a fresh and active threat.
  • Multiple security vendors have issued alerts and mitigation guidance in the past days.
  • The incident highlights an ongoing trend of supply chain attacks targeting open-source ecosystems.
Why it matters
  • Supply chain attacks on popular open-source packages can impact millions of users downstream.
  • Compromised secrets and credentials can lead to further intrusions, ransomware, and financial theft.
  • Understanding and mitigating such attacks is critical for software supply chain security.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • Axios npm packages versions 1.14.1 and 0.30.4 were compromised with malicious code linked to North Korean state actor Sapphire Sleet
  • The attack deployed a second-stage remote access trojan targeting multiple operating systems after connecting to attacker command and control servers
  • The compromise is part of a broader wave of software supply chain attacks causing stolen secrets and enabling further intrusions, ransomware, and cryptocurrency theft
How sources frame it
  • Microsoft Threat Intelligence And Microsoft Defender...: neutral
All evidence
All evidence
Software supply chain hacks trigger wave of intrusions, data theft
Helpnetsecurity · helpnetsecurity.com · 2026-04-02 15:16 UTC
Mitigating the Axios npm supply chain compromise
Microsoft · microsoft.com · 2026-04-01 21:00 UTC
Threat Brief: Widespread Impact of the Axios Supply Chain Attack
Paloaltonetworks · unit42.paloaltonetworks.com · 2026-04-01 18:30 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 3Origin domains: 3Duplicates: -
Showing 3 / 3
Top publishers (this list)
  • Helpnetsecurity (1)
  • Microsoft (1)
  • Paloaltonetworks (1)
Top origin domains (this list)
  • helpnetsecurity.com (1)
  • microsoft.com (1)
  • unit42.paloaltonetworks.com (1)