Google’s cybersecurity team has attributed a recent supply chain attack targeting the popular JavaScript library Axios to the North Korean threat group UNC1069.
Key Findings
- The Malware: Attackers used an improved version of the WAVESHAPER Remote Access Trojan (RAT).
- Infrastructure: Analysts identified an IP address previously linked to historical North Korean cyber operations.
- Affected Versions: The malicious code was found in Axios versions 1.14.1 and 0.30.4.
Required Actions
If you are using the affected versions, take the following steps immediately:
- Remove versions 1.14.1 and 0.30.4 from your projects.
- Rotate all credentials, API keys, and secrets that may have been exposed.
For more details, refer to the official Google Cloud security report.


