North Korean hackers implicated in major supply chain attack
By Sam Sabin
Published on March 31, 2026.
Researchers at Google have linked suspected North Korean hackers to an ongoing compromise of the open-source package Axios, a JavaScript library used millions of times per week. The hackers used the tool to launch malicious versions of the software targeting Macros, Windows, and Linux systems. The malicious versions were removed within three hours of being published, which Google warned could have far-reaching implications due to the package's widespread use. It remains unclear how the attackers gained access to the maintainer's GitHub account.
Read Original Article