North Korea-Linked Hackers Target Axios Library in Major Supply Chain Attack
North Korea-linked hackers compromised the widely-used Axios library in a supply chain attack, injecting malware capable of stealing login credentials across millions of apps on Windows, macOS, and Linux.

A hooded figure illuminated by projected cyber code, representing the North Korea-linked supply chain attack on the Axios JavaScript library.
Hackers linked to North Korea have breached Axios — a behind-the-scenes software library that powers countless apps and web services — injecting malicious code into an update that could have exposed millions of systems worldwide to credential theft.
The attack, attributed by Google to a threat group it tracks as UNC1069, was discovered early on April 1, 2026, after the malicious update was pushed on March 31. The malware has since been removed, but the window of exposure has raised serious alarms across the cybersecurity community.
What is Axios — and why does it matter?
Axios is an open-source JavaScript library that handles communication between apps and web services. It operates entirely in the background — invisible to end users but present in an enormous share of modern web and mobile applications.
"Every time you load a website, check your bank balance, or open an app on your phone, there's a good chance Axios is running somewhere in the background making that work," said Tom Hegel, senior researcher at SentinelOne.
Because Axios is open-source, its code can be freely licensed and modified — which is precisely what made it an attractive target for this type of attack.
How the attack worked
Rather than targeting individual organizations directly, the attackers compromised the Axios update mechanism itself — inserting malicious code into a legitimate software update. Any system or application that downloaded the update during the exposure window could have been silently infected.
The malware was built to run across all three major operating systems — Windows, macOS, and Linux — significantly broadening its potential reach.
"The attacker gained a delivery mechanism with potential reach into millions of environments," said cybersecurity firm Elastic Security, which published an independent analysis of the attack.
Crucially, no user action was required. "You don't have to click anything or make a mistake," said Hegel. "The software you already trust did it for you."
What could attackers access?
Once installed, the malicious software could give attackers access to a compromised system's data — including login credentials and access tokens. These can then be used to conduct further data theft, move laterally within networks, or launch follow-on attacks against downstream targets.
The cyber researchers described the breach as a supply chain attack, in which the hack could enable attacks on downstream entities — meaning the true number of affected organizations may extend well beyond those who downloaded the compromised update directly.
Who is behind it?
Google attributed the attack to UNC1069, a North Korea-linked threat group that has operated since at least 2018. According to a February report by Google's Threat Intelligence Group, the group is known for targeting the cryptocurrency and financial industries, and has recently expanded its capabilities with AI-generated deepfakes, fake Zoom meetings, and seven newly documented malware families.
"North Korean hackers have deep experience with supply chain attacks, which they primarily use to steal cryptocurrency," said John Hultquist, chief analyst for Google's Threat Intelligence Group.
North Korea is known to use stolen cryptocurrency to fund its weapons programs and evade international sanctions, according to the US government.
Why GCC and MENA organizations should take note
The UAE, particularly Dubai, has rapidly established itself as one of the world's leading cryptocurrency and fintech hubs. With UNC1069's established focus on financially motivated attacks against crypto and financial institutions, organizations across the GCC operating in these sectors should treat this incident as a direct threat signal — even if they were not confirmed victims.
Any business running modern web applications or services that use Axios in their technology stack should conduct an immediate audit of their dependency update logs for the period of March 31 to April 1, 2026.
What to do now
- Audit all Axios dependencies and verify current version integrity
- Review system and access logs for unusual credential usage during the exposure window
- Monitor for unauthorized access attempts on financial and crypto platforms
- Ensure software dependency update processes include integrity verification
- Brief security and DevOps teams on supply chain attack indicators of compromise
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.