UNC1069 Axios Supply Chain Attack

Cloud Security Alliance (CSA) / Mandiant (GTIG) pdf 2026-04-15T00:00:00

Abstract

On March 31, 2026, the North Korea-nexus threat actor UNC1069 compromised the lead maintainer of the Axios npm package through an AI-assisted social engineering campaign. The attack delivered the WAVESHAPER.V2 remote access trojan and targeted AI vendor infrastructure, specifically impacting OpenAI's macOS application code-signing process. The incident highlights the vulnerability of open-source maintainers as a privileged access vector into AI build pipelines and reveals a critical weakness where legacy npm tokens can bypass modern OIDC-based provenance infrastructure.

Loading executive summary...
Loading full markdown...

Your browser does not support inline PDF viewing.

Download the PDF to view it.

Match Rate: 10.00/10 (Relevance to core cybersecurity goals)

LINK COPIED TO CLIPBOARD