Skip to main content
See every side of every news story
Published loading...Updated

Suspected North Korean Hackers Compromise Axios Package in Supply-Chain Attack

The malicious updates could expose credentials and downstream systems, and researchers said the package is downloaded more than 100 million times a week.

  • Suspected North Korean hackers compromised the software package Axios on Tuesday, gaining control of a developer's account for three hours and pushing malicious updates to thousands of companies.
  • Pyongyang relies on digital heists to fund nuclear and missile programs, a tactic the regime employed three years ago when infiltrating another popular software provider used by healthcare and hotel firms.
  • John Hammond, security researcher at Huntress, identified about 135 compromised devices belonging to roughly 12 companies, describing the hack as "perfectly timed" given AI agents developing software without review.
  • "We anticipate they will try to leverage the credentials," Charles Carmakal, Mandiant chief technology officer, warned, as experts expect recovery will take months while attackers target cryptocurrency assets.
  • High-Profile, noisy operations are a price Pyongyang is willing to pay because the regime is not worried about its international reputation, Ben Read, director of strategic threat intelligence at Google-owned Wiz, noted.
Insights by Ground AI
Podcasts & Opinions

64 Articles

Lean Right

" Hundreds of thousands of stolen secrets may be circulating as a result of these recent attacks," says Google, warning that there may be more stealths of cryptomouses and 'ransomware' attacks.

·Portugal
Read Full Article
CNNCNN
+10 Reposted by 10 other sources
Lean Left

North Korean hackers bug software used by thousands of US companies in potential crypto heist attempt

Suspected North Korean hackers have bugged a software package that has been used by thousands of US companies in a major supply-chain attack that could take months to recover from, security experts said Tuesday.

·Atlanta, United States
Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 74% of the sources are Center
74% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

IT Security News - cybersecurity, infosecurity news broke the news in on Tuesday, March 31, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal