UNC1069 Axios Supply Chain Attack
Cloud Security Alliance (CSA) / Mandiant (GTIG)
pdf
2026-04-15T00:00:00
Abstract
On March 31, 2026, the North Korea-nexus threat actor UNC1069 compromised the lead maintainer of the Axios npm package through an AI-assisted social engineering campaign. The attack delivered the WAVESHAPER.V2 remote access trojan and targeted AI vendor infrastructure, specifically impacting OpenAI's macOS application code-signing process. The incident highlights the vulnerability of open-source maintainers as a privileged access vector into AI build pipelines and reveals a critical weakness where legacy npm tokens can bypass modern OIDC-based provenance infrastructure.
Loading executive summary...
Loading full markdown...
Match Rate:
10.00/10
(Relevance to core cybersecurity goals)