MIDNIGHT NEPTUNE: Threat Actor Behind Axios Compromise
Google Threat Intelligence Group attributes the axios npm compromise to MIDNIGHT NEPTUNE, formerly known as UNC1069. The actor is linked to North…
Google Threat Intelligence Group attributes the axios npm compromise to MIDNIGHT NEPTUNE, formerly known as UNC1069. The actor is linked to North…
Amazon Threat Intelligence has attributed the September 2025 hijack of the popular npm packages debug and chalk to North Korea's Sapphire Sleet…
WAVESHAPER.V2 is a backdoor malware used by UNC1069/Sapphire Sleet, identified in the axios npm compromise. It provides remote access and data exfiltration…
Synk (likely Snyk), a developer security company, analyzed the Mastra campaign and noted strong similarities to the Axios npm compromise, including clean-then-armed…
axios is a popular npm package for making HTTP requests. It was compromised in March 2026 by Sapphire Sleet/UNC1069 via a post-install…
On June 17, 2026, a software supply chain attack codenamed 'easy-day-js' compromised 145 npm packages under the @mastra/* namespace, a popular open-source…
UNC1069 is a threat group attributed to North Korea, associated with the WAVESHAPER.V2 backdoor and activities overlapping with Sapphire Sleet. It has…