North Korean threat group MIDNIGHT NEPTUNE compromised the maintainer account of the axios npm package to inject a malicious dependency dropping WAVESHAPER.V2 backdoor.
Mar 1, 2026
154d agoKey Details
- Maintainer account compromised via social engineering in March 2026
- Malicious update deployed WAVESHAPER.V2 backdoor to downstream users
- Package removed from npm registry within 3 hours of release