Published

Technology and Science31 March, 20261 min read

North Korean Hackers Hijack Axios Library Using Sophisticated Social Engineering

This article is an automated aggregation of coverage from news outlets. Our editorials offer in-depth analysis curated by the NewsCord team.

Two malicious Axios npm versions published March 31. Weeks-long social engineering targeted Axios maintainers to gain access.

North Korean Hackers Hijack Axios Library Using Sophisticated Social Engineering
Image: Tom's Hardware

The Two-Week Hack

North Korean hackers executed a two-week social engineering campaign to hijack the Axios library. They created a convincing Slack workspace with fake employee profiles. The target was tricked into downloading malware granting remote access to their system.

Attackers pushed two malicious Axios packages live for roughly three hours. Axios has 45 million weekly downloads, so millions could have been exposed.

Reporting for this sectionTechCrunchSilicon CanalsSecurityWeek

Broader Campaign Against Developers

The Axios hack was part of a sustained North Korean campaign targeting multiple Node.js maintainers. The same tradecraft was used against several other prominent developers.

Google researchers had documented similar techniques by Lazarus Group before. The operation's professionalism and patience make it particularly dangerous.

Reporting for this sectionSecurityWeekSilicon Canalsmezha.net

Wider Implications

The Axios compromise raised urgent questions about open-source software supply chain security. The attack exploited the inherent trust developers place in each other's code.

Government actors and criminals are increasingly focusing on mass-market tools. Well-resourced state actors can exploit social engineering to infiltrate vital software ecosystems.

Reporting for this sectionTechCrunchmezha.netSilicon Canals