
- Google Threat Intelligence Group warns of active supply chain attack on npm’s Axios library
- Malicious dependency “plain-crypto-js” deployed WAVESHAPER.V2 backdoor across Windows, macOS, and Linux
- Attribution points to North Korea’s UNC1069 group, known for long-running campaigns targeting cryptocurrency and software developers