Security12 views

Google Links Axios Library Attack to North Korean Group

Google’s cybersecurity team has attributed a recent supply chain attack targeting the popular JavaScript library Axios to the North Korean threat group UNC1069.

Key Findings

  • The Malware: Attackers used an improved version of the WAVESHAPER Remote Access Trojan (RAT).
  • Infrastructure: Analysts identified an IP address previously linked to historical North Korean cyber operations.
  • Affected Versions: The malicious code was found in Axios versions 1.14.1 and 0.30.4.

Required Actions

If you are using the affected versions, take the following steps immediately:

  1. Remove versions 1.14.1 and 0.30.4 from your projects.
  2. Rotate all credentials, API keys, and secrets that may have been exposed.

For more details, refer to the official Google Cloud security report.