Get all your news in one place.
100's of premium titles.
One app.
Start reading
Windows Central
Windows Central
Technology
Cale Hunt

"This was not opportunistic. It was precision." — How North Korean hackers used Microsoft Teams and Slack to compromise Windows PCs with an elaborate ploy

North Korean national flags are displayed outside the hall of Chongryon, the General Association of Korean Residents in Japan, during its two-day-long general assembly meeting in Tokyo on May 26, 2018.

It's been about a week since suspected hackers out of North Korea temporarily compromised axios, one of the world's most popular JavaScript HTTP client libraries. Now, more details are emerging about how the hack was achieved, and why it's pertinent knowledge for Windows, macOS, and Linux users.

The original hijacking occurred when bad actors were able to compromise axios maintainer Jason Saayman's primary account. This allowed for the publishing of two malicious axios versions to npm (a massive public registry of tools available for download) on March 30, 2026.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.