- UNC1069North Korean threat actor attributed to the Axios supply chain attack
- plain-crypto-js (v4.2.1)Phantom dependency published as post-install RAT dropper in Axios attack
- WaveShapermacOS binary used in attack, overlaps with UNC1069 infrastructure
- Axios (v1.14.1, v0.30.4)Backdoored NPM package versions deployed in supply chain attack
- @shadanai/openclawPackage distributing same malware as Axios attack
- @qqbrowser/[email protected]Package distributing same malware as Axios attack
ThreatNoir Afternoon Brief — April 1
Afternoon Review in IT Security — April 1, 2026
The security landscape continues to face significant challenges as critical vulnerabilities and supply chain attacks dominate the threat landscape. Today's review covers a North Korean-linked supply chain compromise affecting a widely-used JavaScript library, a critical ImageMagick zero-day impacting Linux and WordPress systems, Google's ongoing battle with Chrome exploits, and an accidental source code exposure from a major AI company.
Axios NPM Package Breached in North Korean Supply Chain Attack
A sophisticated supply chain attack has compromised the popular Axios NPM package through the exploitation of a long-lived NPM access token. Threat actors bypassed the GitHub Actions OIDC-based CI/CD publishing workflow to inject backdoored versions of the package into the repository. The attack is attributed to North Korean threat actors and demonstrates the persistent risk posed by credential compromise in software distribution pipelines. Affected versions include Axios v1.14.1 and v0.30.4, along with related malicious packages such as @qqbrowser/[email protected], @shadanai/openclaw, plain-crypto-js v4.2.1, and tools associated with the UNC1069 group and WaveShaper malware. Source: Axios NPM Package Breached in North Korean Supply Chain Attack
ImageMagick Zero-Day Enables RCE on Linux and WordPress Servers
Research from Octagon Networks has uncovered a critical zero-day vulnerability in ImageMagick that enables remote code execution through simple image uploads. The vulnerability affects Ubuntu, Amazon Linux, and WordPress installations, exploiting a magic byte shift technique that bypasses even stringent security policies. The attack chain leverages GhostScript exploitation and Magick Scripting Language sandbox escape mechanisms to achieve arbitrary code execution on vulnerable systems. This vulnerability represents a significant threat to web servers and content management systems that rely on ImageMagick for image processing. Source: ImageMagick Zero-Day Enables RCE on Linux and WordPress Servers
Google Fixes Fourth Chrome Zero-Day Exploited in Attacks in 2026
Google has patched the fourth Chrome vulnerability exploited in zero-day attacks since the beginning of 2026, continuing a troubling trend of active exploitation. The newly patched vulnerabilities include CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, and CVE-2026-5281, each representing active threats in the wild. The frequency of zero-day exploits targeting Chrome underscores the browser's prominence as an attack vector and the sophisticated capabilities of threat actors actively targeting the platform. Source: Google fixes fourth Chrome zero-day exploited in attacks in 2026
Claude Code Source Leaked via npm Packaging Error, Anthropic Confirms
Anthropic has confirmed that internal source code for Claude Code, its AI-powered coding assistant, was inadvertently released through a packaging error on npm. The company stated that no sensitive customer data or credentials were exposed in the incident, attributing the leak to human error in the release process rather than a security breach. The exposure highlights ongoing vulnerabilities in software distribution practices and the importance of rigorous release management procedures, particularly for widely-used packages in the open-source ecosystem. Source: Claude Code Source Leaked via npm Packaging Error, Anthropic Confirms
The convergence of supply chain attacks, critical infrastructure vulnerabilities, and packaging errors demonstrates the multifaceted nature of modern cybersecurity threats. Organizations must prioritize patch management, credential security, and release process controls to mitigate these evolving risks.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- ImageMagick RCE via magic byte shiftZero-day technique exploiting image file processing to achieve remote code execution
- Magick Scripting Language (MSL) sandbox escapeAttack technique to move files across the filesystem and establish persistence
- GhostScript exploitation chainSecondary tool receives malicious files from ImageMagick, enabling command execution
- Use-after-free in Chrome WebGPU (Dawn) implementation, actively exploited in attacks
- Iterator invalidation in CSSFontFeatureValuesMap, patched mid-February 2026
- Out-of-bounds write in Skia 2D graphics library, exploited in attacks early April 2026
- Inappropriate implementation in V8 JavaScript/WebAssembly engine, exploited in attacks early April 2026
- Trojanized HTTP client (Axios supply chain attack)Cross-platform RAT delivered via compromised Claude Code npm package on March 31, 2026 between 00:21–03:29 UTC