criticalOther UnknownPublish anonymously
Axios npm supply chain attack — North Korean Sapphire Sleet targets 70M weekly downloads
by Publish anonymously · 2 days agoviews 2en
PII protected
Personal information such as emails, phone numbers, IDs and access tokens are automatically masked before publication.
North Korean state actor Sapphire Sleet compromised the npm account of an axios maintainer, publishing malicious versions with a hidden dependency deploying a cross-platform RAT via post-install hook. Significant because AI coding agents autonomously run npm install. Active ~3 hours.