Summary
North Korean hackers have compromised a widely used open-source package called axios, which is utilized by millions of developers across various platforms. The malicious update, versions 1.14.1 and 0.30.4, includes backdoors that can infect Windows, macOS, and Linux systems. When installed, these packages download additional malware from a command-and-control server (sfrclak[.]com) and establish persistence mechanisms.
Key Points
- Compromised Package: Axios versions 1.14.1 and 0.30.4
- Malware Downloaded:
plain-crypto-jsversion 4.2.0 or 4.2.1, which contains a backdoor with C2 capabilities. - Impact: The malware can exfiltrate system information and establish persistence across multiple platforms.
- Recommendations:
- Avoid using the compromised versions of axios (1.14.1 and 0.30.4).
- Pin projects to known-good releases such as 1.14.0 or earlier, and 0.30.3 or earlier.
- Check lockfiles for `plain-crypto
Read the full article at Cyber Security News
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.

![[AINews] The Unreasonable Effectiveness of Closing the Loop](/_next/image?url=https%3A%2F%2Fmedia.nemati.ai%2Fmedia%2Fblog%2Fimages%2Farticles%2F600e22851bc7453b.webp&w=3840&q=75)



