North Korean Hackers Fake a Company to Pwn Axios Maintainer – RAT in 100M Downloads
Picture this: a Teams call with 'colleagues' from a polished fake company. One 'update' click later, North Koreans control your machine and poison a library with 100 million downloads. Open source just got conned.
DevTools FeedApr 03, 20264 min read14 views
⚡ Key Takeaways
North Koreans used pro-level social engineering: fake Slack/Teams/company to RAT an axios maintainer.𝕏
npm lacks OIDC enforcement; 2FA useless against full machine control.𝕏
Scanners caught it fast, but 3 hours exposed millions—verify provenance always.𝕏
The 60-Second TL;DR
North Koreans used pro-level social engineering: fake Slack/Teams/company to RAT an axios maintainer.
npm lacks OIDC enforcement; 2FA useless against full machine control.
Scanners caught it fast, but 3 hours exposed millions—verify provenance always.