Full story
The Two-Week Hack
North Korean hackers executed a two-week social engineering campaign to hijack the Axios library.
“The hackers began their targeting campaign around two weeks before eventually gaining control of his computer”
They created a convincing Slack workspace with fake employee profiles.

The target was tricked into downloading malware granting remote access to their system.
Attackers pushed two malicious Axios packages live for roughly three hours.
Axios has 45 million weekly downloads, so millions could have been exposed.
Broader Campaign Against Developers
The Axios hack was part of a sustained North Korean campaign targeting multiple Node.js maintainers.
The same tradecraft was used against several other prominent developers.

Google researchers had documented similar techniques by Lazarus Group before.
The operation's professionalism and patience make it particularly dangerous.
Wider Implications
The Axios compromise raised urgent questions about open-source software supply chain security.
“This kind of hack highlights the security challenges that developers of popular open source projects can face”
The attack exploited the inherent trust developers place in each other's code.
Government actors and criminals are increasingly focusing on mass-market tools.
Well-resourced state actors can exploit social engineering to infiltrate vital software ecosystems.
