logo

Axios_summary

ID: 60f0ad4a-a902-4522-848d-25d5b3e6d168

STIX ID: report--60f0ad4a-a902-4522-848d-25d5b3e6d168

Threat Score

50/100

Uploaded: 2026-05-23

Created by: team456

TLP:GREEN
...
...
Unit 42 observed a significant supply-chain attack on the Axios JavaScript library after an npm maintainer account was hijacked, leading to malicious releases (v1.14.1 and v0.30.4) that added a hidden dependency, plain-crypto-js. That dependency is a cross-platform RAT targeting Windows, macOS and Linux for reconnaissance, persistence and evasion; analysis links the malware to DPRK-associated activity and the campaign impacted multiple sectors across the U.S., Europe, Middle East, South Asia and Australia.