North Korea behind social engineering attack on Axios project

Key summary
The Axios maintainer's npm account was compromised via a social engineering attack attributed to North Korea–linked group UNC1069.
Two malicious Axios package versions were published on March 31 through the compromised maintainer npm account.
The tampered releases installed a cross-platform Remote Access Trojan via a fake dependency on macOS, Windows, and Linux.
UNC1069, active since 2018 and described as financially motivated, uses AI tools and deepfakes (fake Zoom meetings and Telegram messages); Chalk and Debug were similarly hijacked in September 2025.
After the breach the maintainer wiped systems, reset accounts, and plans to adopt a FIDO security key; GitHub warned about this attack type in 2023 and Microsoft reiterated the warning later.



