LOWSupply Chain
Global

Axios NPM Package Breached in North Korean Supply Chain Attack

Wednesday, April 1, 2026 at 08:45 AM UTC·Source: SecurityWeek

Updated: Wednesday, April 1, 2026 at 07:13 PM UTC

Executive Summary

A long-lived NPM access token was used to bypass the GitHub Actions OIDC-based CI/CD publishing workflow and push backdoored package versions. The post Axios NPM Package Breached in North Korean Supply Chain Attack appeared first on SecurityWeek .

Analysis

A long-lived NPM access token was used to bypass the GitHub Actions OIDC-based CI/CD publishing workflow and push backdoored package versions. The post Axios NPM Package Breached in North Korean Supply Chain Attack appeared first on SecurityWeek .
Source Attribution

Originally published by SecurityWeek on Apr 1, 2026.

Related Threats