A North Korea-linked threat actor (UNC1069) hijacked the npm account of an axios maintainer and published two backdoored versions. They were live for ~3 hours before npm removed them.
- 00:21 — Malicious
[email protected]published (latest dist-tag) - 00:39 — Malicious
[email protected]published (legacy dist-tag) - ~03:15 — npm removes compromised versions