UNC1069
Coverage of UNC1069 in the Nexus archive.
- A little-known npm package was North Korea’s warm-up act for the axios hack
Amazon's security researchers revealed that a North Korea-linked hacking group targeted small npm packages like typo-crypto, debug, and chalk as a rehearsal before attacking the widely used axios library. The group used trusted maintainers to publish malicious updates, testing methods that later scaled to larger software. The typo-crypto attack in March 2025 involved a malicious file that activated with a specific numeric input and downloaded platform-specific code.
- North Korean hackers implicated in major supply chain attack
North Korean hackers linked to the UNC1069 group are suspected of compromising the Axios npm package, injecting credential-stealing malware into a widely used JavaScript library. The malicious versions were removed quickly, but the attack highlights risks due to Axios's massive adoption across cloud and code environments.