LOWSupply Chain
Global
Axios NPM Package Breached in North Korean Supply Chain Attack
Wednesday, April 1, 2026 at 08:45 AM UTC·Source: SecurityWeek
Updated: Wednesday, April 1, 2026 at 07:13 PM UTC
Executive Summary
A long-lived NPM access token was used to bypass the GitHub Actions OIDC-based CI/CD publishing workflow and push backdoored package versions. The post Axios NPM Package Breached in North Korean Supply Chain Attack appeared first on SecurityWeek .
Analysis
A long-lived NPM access token was used to bypass the GitHub Actions OIDC-based CI/CD publishing workflow and push backdoored package versions. The post Axios NPM Package Breached in North Korean Supply Chain Attack appeared first on SecurityWeek .