Related Families: Mini Shai-Hulud, ChainDrop
Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack
Aug 10, 2026, 3:15:02 PM / by The Hivemind posted in Threat Bulletin, npm malware, Software Supply Chain Security, Mini Shai-Hulud, JavaScript malware, GitHub Actions OIDC, npm supply chain attack
The Axios Breach: When npm Trust Becomes an APT Attack Vector
Apr 6, 2026, 2:36:03 PM / by The Hivemind posted in Threat Bulletin, North Korean threat actors, UNC1069, CI/CD compromise, npm malware, supply chain attacks, Axios npm compromise, WAVESHAPER, DPRK cyber operations, RAT malware
Verticals Targeted: Software, Technology, Cloud, Enterprise IT environments
Regions Targeted: Global
Related Families: WAVESHAPER.V2
Executive Summary
A supply chain compromise of the widely used Axios npm package introduced a malicious dependency delivering cross-platform remote access trojans, now linked with high confidence to a North Korea–aligned threat cluster UNC1069. The campaign leveraged maintainer account takeover, npm publishing abuse, and install-time execution to target developer environments and CI/CD pipelines during a short but high-risk exposure window.
Infect Once, Spread Everywhere: CanisterWorm and the Automation of Supply Chain Compromise
Mar 31, 2026, 11:07:10 AM / by The Hivemind posted in Threat Bulletin, DevSecOps security, decentralized C2, ICP malware, CanisterWorm, CI/CD compromise, Kubernetes security, software supply chain attack, npm malware, TeamPCP, container security, token harvesting malware
Related Families: CanisterWorm