Kaspersky Links Axios Supply Chain Attack to BlueNoroff
Researchers from Kaspersky’s Global Research and Analysis Team (GReAT) uncovered technical links between the headline-grabbing supply chain attack on Axios, one of the world’s most widely used JavaScript libraries, and previously documented campaigns associated with BlueNoroff, a financially motivated subgroup of the infamous Lazarus Group.
Axios is one of the most widely used JavaScript HTTP client libraries, with over 100 million weekly downloads on npm. In March 2026, attackers compromised the npm account of a lead Axios maintainer and used it to publish malicious versions of the package.
These versions introduced a hidden dependency called plain-crypto-js, which was not used by the library itself but executed during installation via a postinstall script. This dependency downloaded and deployed a cross-platform Remote Access Trojan targeting macOS, Windows, and Linux systems.
BlueNoroff is a financially motivated subgroup of the Lazarus Group, known for targeting financial institutions and cryptocurrency platforms. The group has a...
Copyright of this story solely belongs to itvoice.in. To see the full text click HERE