UNC1069 trasforma Axios in un vettore di spionaggio: WAVESHAPER.V2 colpisce la supply chain npm

Il 31 marzo 2026, UNC1069 — il gruppo APT nordcoreano noto anche come Sapphire Sleet — ha compromesso l'account di un maintainer di Axios per distribuire il backdoor cross-platform WAVESHAPER.V2 tramite una falsa dipendenza npm. Tre ore di esposizione, 19 organizzazioni colpite e l'intera community JavaScript con le mani nei capelli.

https://insicurezzadigitale.com/unc1069-trasforma-axios-in-un-vettore-di-spionaggio-waveshaper-v2-colpisce-la-supply-chain-npm/

Fuites de données : la fracture numérique s’élargit

Les fuites de données ne relèvent plus de l’accident isolé. Elles se multiplient, touchent des secteurs de plus en plus variés et installent l’idée d’une vulnérabilité devenue ordinaire.
Services publics, loisirs, sport, culture... Plus un seul espace numérique ne semble désormais épargné.
À chaque incident, ce sont des informations personnelles qui circulent, s’exposent, se monnayent parfois. Derrière la répétition de ces affaires, une même question demeure : avons-nous réellement pris la mesure de la fragilité de nos environnements numériques ?
Car ces brèches à répétition dessinent une faille plus profonde qu’il n’y paraît.

https://librexpression.fr/les-nouvelles-lignes-de-faille-du-numerique-2-4

(Crédits : Rendan Catipay/Pexels)

#Chine #Cyberattack #Databreaches #France #informatique #Librexpression #Phishing #RansomHouse #ransomware #Russie #spearphishing #supplychain #threats #UNC1069 #USA #warfare

Fake-Teams-Update: So haben Angreifer den axios-Maintainer ausgetrickst

Der axios-Maintainer beschreibt, wie Cyberkriminelle den HTTP-Client mit Schadcode verseuchen konnten. Derweil gibt es ähnliche Attacken auf weitere Maintainer.

heise online

Watch out as North Korean group #UNC1069 targets Node.js maintainers using fake LinkedIn and Slack profiles to spread malware and compromise open source packages.

Read: https://hackread.com/unc1069-node-js-maintainer-fake-linkedin-slack-profile/

#CyberSecurity #NorthKorea #LinkedIn #Slack #Malware

UNC1069 Targets Node.js Maintainers via Fake LinkedIn, Slack Profiles

North Korean group UNC1069 targets Node.js maintainers using fake LinkedIn and Slack profiles to spread malware and compromise open source packages.

Hackread - Cybersecurity News, Data Breaches, AI and More

🚨 Over the past two weeks, two massive, overlapping campaigns—TeamPCP’s "blitzkrieg" on security tools like Trivy and Checkmarx, and UNC1069's devastating RAT deployment via the Axios library—have compromised thousands of CI/CD pipelines.

Read the full deep-dive and get the immediate mitigation steps here: https://www.security.land/2026-supply-chain-attacks-teampcp-trivy-axios/

#SecurityLand #BreachBreakdown #SupplyChainAttack #NPM #Cybersecurity #Axios #Trivy #TeamPCP #UNC1069

March 2026 Supply Chain Attacks: TeamPCP & Axios Analyzed

A technical breakdown of the March 2026 supply chain attacks, examining how threat actors like TeamPCP and UNC1069 compromised Trivy, LiteLLM, and Axios—and how to stop them.

Security Land | Decoding the Cyber Threat Landscape
Google links Axios npm supply chain attack to North Korea-linked APT UNC1069

Google links the Axios npm supply chain attack to North Korean threat group UNC1069, targeting financial gain.

Security Affairs
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack
#AxiosProject #UNC1069 #WAVESHAPER
https://cloud.google.com/blog/topics/threat-intelligence/north-korea-threat-actor-targets-axios-npm-package
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack | Google Cloud Blog

A North Korea-nexus threat actor targeted the popular axios NPM package in a massive supply chain attack.

Google Cloud Blog
Nordkoreanische Hacker professionalisieren KI-Angriffe – Finanzbranche im Fadenkreuz! Laut Sicherheitsforschern von Mandiant setzen nordkoreanische Hacker der Gruppe UNC1069 inzwischen hochentwickelte KI‑Tools, Deepfakes und Social Engineering ein, um gezielt Unternehmen der Finanz- und Kryptobranche anzugreifen. #CyberSecurity #AIThreats #UNC1069 #FinancialServices #Krypto #Deepfake #Cybercrime #Nordkorea #Hackerangriff
UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering | Google Cloud Blog

North Korean threat actors target the cryptocurrency industry using AI-enabled social engineering such as deepfakes, and ClickFix.

Google Cloud Blog
GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools | Google Cloud Blog

Google Threat Intelligence Group's findings on adversarial misuse of AI, including Gemini and other non-Google tools.

Google Cloud Blog