Google has now linked the hack and hijack of the popular Axios npm open-source project to North Korea (UNC1069), which is known for stealing cryptocurrency.
Axios is downloaded tens of millions of times weekly, so this hack is likely widespread.
Our updated story: https://techcrunch.com/2026/03/31/hacker-hijacks-axios-open-source-project-used-by-millions-to-push-malware?nocache=1


