Skip to main content
See every side of every news story
Published loading...Updated

Social Engineering Attacks on Open Source Developers Are Escalating

North Korean hackers spent weeks socially engineering an Axios maintainer through a fake Slack workspace, a cloned company identity, and a fabricated Microsoft Teams call that tricked him into installing a RAT posings as a software update. They used the access they gained to inject malware into npm packages downloaded 100+ million times a week. Now, a fresh Open Source Security Foundation (OpenSSF) advisory warns unknown attackers are using a si…

4 Articles

A software used by hundreds of millions of developers every week, compromised in a few hours by North Korean hackers. On March 31, 2026, Axios, a must-have JavaScript library, almost became a weapon of mass hacking. Hacking open source software targeted its main developer Hacking open source software as popular as Axios did not start with a technical flaw. Everything started two weeks before the attack with a carefully orchestrated approach. hac…

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

Help Net Security broke the news in on Wednesday, April 8, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal