[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$flLpb2OF2kIj8NC3np9I_QdRrAoVpDptfY8RcGmsZaFA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"23911ee8-1ec1-48f0-9cfc-099a6e2a0e42","north-korean-apt-compromises-axios-npm-package-via-token-hijacking","c62bbeaa-6c1a-4184-91f1-eba24d5f983a","North Korean APT Compromises Axios NPM Package via Token Hijacking","North Korean threat actors successfully compromised the widely-used Axios NPM package by exploiting a long-lived access token, bypassing CI\u002FCD security controls to inject malicious code into trusted software dependencies. The attack demonstrates how sophisticated threat actors can weaponize the software supply chain to achieve massive distribution, reaching approximately 80% of cloud environments through a single compromised package. The use of phantom dependencies and self-destructing payloads shows advanced evasion techniques designed to maximize impact while minimizing forensic evidence. This incident highlights the critical importance of securing software supply chains and implementing robust access controls for package management systems.","**Immediate actions:**\n- Audit and rotate all NPM access tokens, implementing short-lived tokens where possible\n- Scan all environments for Axios versions 1.14.1 and 0.30.4 and immediately downgrade to safe versions\n- Enable package integrity verification and dependency scanning in CI\u002FCD pipelines\n\n**Long-term improvements:**\n- Implement multi-factor authentication and approval workflows for package publishing\n- Deploy software composition analysis tools to monitor for suspicious dependencies and package changes\n- Establish automated dependency pinning and controlled update processes\n\n**Detection measures:**\n- Monitor package repositories for unexpected updates or new maintainers on critical dependencies\n- Implement behavioral analysis to detect post-install script execution and suspicious network connections\n- Enable comprehensive logging of package installation and execution activities",[12,13,14,15,16,17],"CIS Control 2.1","CIS Control 16.7","NIST SP 800-161","NIST AC-2","NIST SI-7","SLSA Framework","published","2026-04-01T10:08:18.746309+00:00","2026-04-01T10:08:18.612+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fwww.securityweek.com\u002Faxios-npm-package-breached-in-north-korean-supply-chain-attack\u002F","axios-npm-package-breached-in-north-korean-supply-chain-attack","Axios NPM Package Breached in North Korean Supply Chain Attack",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":33,"name":34,"slug":35,"description":36,"color":37},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[39],{"id":40,"date":41,"edition":42,"title":43,"audio_url":44},"f7c25fde-6357-4223-8408-d43b202bef66","2026-04-01","afternoon","ThreatNoir Afternoon Brief — April 1","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-04-01\u002Fthreatnoir-afternoon-brief-2026-04-01.mp3"]