Weekly review

ThreatNoir Afternoon Brief — April 1

2026-04-01Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — April 1, 2026

The security landscape continues to face significant challenges as critical vulnerabilities and supply chain attacks dominate the threat landscape. Today's review covers a North Korean-linked supply chain compromise affecting a widely-used JavaScript library, a critical ImageMagick zero-day impacting Linux and WordPress systems, Google's ongoing battle with Chrome exploits, and an accidental source code exposure from a major AI company.

Axios NPM Package Breached in North Korean Supply Chain Attack

A sophisticated supply chain attack has compromised the popular Axios NPM package through the exploitation of a long-lived NPM access token. Threat actors bypassed the GitHub Actions OIDC-based CI/CD publishing workflow to inject backdoored versions of the package into the repository. The attack is attributed to North Korean threat actors and demonstrates the persistent risk posed by credential compromise in software distribution pipelines. Affected versions include Axios v1.14.1 and v0.30.4, along with related malicious packages such as @qqbrowser/[email protected], @shadanai/openclaw, plain-crypto-js v4.2.1, and tools associated with the UNC1069 group and WaveShaper malware. Source: Axios NPM Package Breached in North Korean Supply Chain Attack

ImageMagick Zero-Day Enables RCE on Linux and WordPress Servers

Research from Octagon Networks has uncovered a critical zero-day vulnerability in ImageMagick that enables remote code execution through simple image uploads. The vulnerability affects Ubuntu, Amazon Linux, and WordPress installations, exploiting a magic byte shift technique that bypasses even stringent security policies. The attack chain leverages GhostScript exploitation and Magick Scripting Language sandbox escape mechanisms to achieve arbitrary code execution on vulnerable systems. This vulnerability represents a significant threat to web servers and content management systems that rely on ImageMagick for image processing. Source: ImageMagick Zero-Day Enables RCE on Linux and WordPress Servers

Google Fixes Fourth Chrome Zero-Day Exploited in Attacks in 2026

Google has patched the fourth Chrome vulnerability exploited in zero-day attacks since the beginning of 2026, continuing a troubling trend of active exploitation. The newly patched vulnerabilities include CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, and CVE-2026-5281, each representing active threats in the wild. The frequency of zero-day exploits targeting Chrome underscores the browser's prominence as an attack vector and the sophisticated capabilities of threat actors actively targeting the platform. Source: Google fixes fourth Chrome zero-day exploited in attacks in 2026

Claude Code Source Leaked via npm Packaging Error, Anthropic Confirms

Anthropic has confirmed that internal source code for Claude Code, its AI-powered coding assistant, was inadvertently released through a packaging error on npm. The company stated that no sensitive customer data or credentials were exposed in the incident, attributing the leak to human error in the release process rather than a security breach. The exposure highlights ongoing vulnerabilities in software distribution practices and the importance of rigorous release management procedures, particularly for widely-used packages in the open-source ecosystem. Source: Claude Code Source Leaked via npm Packaging Error, Anthropic Confirms

The convergence of supply chain attacks, critical infrastructure vulnerabilities, and packaging errors demonstrates the multifaceted nature of modern cybersecurity threats. Organizations must prioritize patch management, credential security, and release process controls to mitigate these evolving risks.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Axios NPM Package Breached in North Korean Supply Chain Attack
Malware6
  • UNC1069
    North Korean threat actor attributed to the Axios supply chain attack
  • plain-crypto-js (v4.2.1)
    Phantom dependency published as post-install RAT dropper in Axios attack
  • WaveShaper
    macOS binary used in attack, overlaps with UNC1069 infrastructure
  • Axios (v1.14.1, v0.30.4)
    Backdoored NPM package versions deployed in supply chain attack
  • @shadanai/openclaw
    Package distributing same malware as Axios attack
  • @qqbrowser/[email protected]
    Package distributing same malware as Axios attack
ImageMagick Zero-Day Enables RCE on Linux and WordPress Servers
Malware3
  • ImageMagick RCE via magic byte shift
    Zero-day technique exploiting image file processing to achieve remote code execution
  • Magick Scripting Language (MSL) sandbox escape
    Attack technique to move files across the filesystem and establish persistence
  • GhostScript exploitation chain
    Secondary tool receives malicious files from ImageMagick, enabling command execution