Morning Review in IT Security — April 2, 2026
The threat landscape continues to evolve with significant developments across supply chain security, zero-day exploits, and credential-based attacks. Today's review covers critical incidents affecting widely deployed software libraries and enterprise communication platforms, alongside emerging malicious services targeting cloud authentication mechanisms.
Mitigating the Axios npm Supply Chain Compromise
On March 31, 2026, the popular HTTP client Axios experienced a significant supply chain attack when two newly published npm packages for version updates (1.14.1 and 0.30.4) were configured to download from command and control infrastructure. Microsoft Threat Intelligence has attributed the attack to Sapphire Sleet, a North Korean state actor. Given that Axios ranks among the most widely used HTTP client libraries in the JavaScript ecosystem, the compromise potentially exposed hundreds to millions of users to malicious code execution. Although the malicious versions have been removed from npm, the incident underscores the vulnerability of open-source dependencies to state-sponsored threats. Source: Mitigating the Axios npm supply chain compromise
Axios npm Package Compromised via Stolen Maintainer Credentials
A threat actor leveraged stolen maintainer credentials to compromise the Axios Node Package Manager package on March 31, 2026, deploying platform-specific ZshBucket variants across affected systems. CrowdStrike Counter Adversary Operations has attributed the attack to an advanced threat actor exploiting legitimate access to the package repository. The incident demonstrates how compromised credentials for high-visibility open-source projects can serve as a vector for widespread malware distribution. Source: 🚨 Breaking: On March 31, 2026, a threat actor used stolen maintainer credentials to compromise t...
Hackers Exploit TrueConf Zero-Day to Push Malicious Software Updates
Attackers have exploited a zero-day vulnerability in TrueConf conference servers to execute arbitrary files on all connected endpoints. The vulnerability, tracked as CVE-2026-3502, allows threat actors to abuse the software update mechanism for malware distribution. Security researchers have identified multiple malicious payloads associated with the campaign, including tools attributed to Amaranth Dragon and the Havoc C2 framework. The exploitation of update mechanisms represents a particularly dangerous attack vector, as legitimate software updates are typically trusted by end users and security controls. Source: Hackers exploit TrueConf zero-day to push malicious software updates
New EvilTokens Service Fuels Microsoft Device Code Phishing Attacks
A new malicious service called EvilTokens has emerged to facilitate device code phishing attacks targeting Microsoft accounts. The service integrates advanced capabilities that enable attackers to hijack Microsoft credentials and conduct sophisticated business email compromise operations. By automating device code phishing workflows, EvilTokens lowers the technical barrier for threat actors seeking to gain persistent access to enterprise environments. The service represents a concerning evolution in credential theft techniques, particularly given the widespread adoption of Microsoft cloud services across organizations. Source: New EvilTokens service fuels Microsoft device code phishing attacks
Organizations should prioritize patching the TrueConf zero-day, auditing npm package dependencies for malicious versions, and implementing enhanced monitoring for device code authentication flows. The convergence of supply chain attacks, zero-day exploits, and credential-focused threats reflects an increasingly sophisticated threat environment requiring layered defensive strategies.