Monday, August 3, 2026

Apps & Consumer

Axios project hijacked in suspected North Korean cyberattack

Suspected North Korean hackers hijacked the Axios open-source project via social engineering, potentially infecting thousands of systems worldwide before the malicious code was removed.

Axios project hijacked in suspected North Korean cyberattack

The Axios open source project—defined as software whose source code is available for modification or enhancement by anyone—was hijacked on March 31. Axios is widely used by developers to connect their applications to the internet. During the incident, suspected North Korean hackers published two malicious packages that remained live for some three hours before being removed. Although the window was short, the malicious code may have infected thousands of systems worldwide. Any computer that installed the compromised versions during this time may have allowed the hackers to steal private keys, credentials, and passwords, potentially leading to further breaches across the web.

Jason Saayman, the maintainer of the Axios project, provided a postmortem detailing how the compromise occurred. The hijacking was successful in part because it relied on well-resourced hackers building rapport and trust with their intended target over a long period of time. Saayman shared that the hackers began their targeting campaign around two weeks before eventually gaining control of his computer to push out malicious code. He explained that the attackers used social engineering—the psychological manipulation of people into performing actions or divulging confidential information—to trick him. Posing as a real company, the hackers created a realistic-looking Slack workspace and used fake employee profiles to invite Saayman to a web meeting. This meeting prompted him to download malware masquerading as a necessary update, granting the hackers remote access to his system. According to Saayman, the tactic mirrored earlier hacks attributed to North Korea by security researchers at Google.

The incident highlights the broader threat posed by state-backed actors targeting widely used software. North Korean hackers remain one of the most active cyber threats on the internet today, blamed for the theft of at least $2 billion in cryptocurrency in 2025. These highly organized groups frequently spend weeks or months executing complex campaigns to gain trust and access, aiming to steal cryptocurrency and data to extort their victims globally.

Why it matters

This incident underscores the vulnerability of widely used open-source software to sophisticated state-sponsored social engineering, posing a global security risk to developers and their users.