Security
Researchers from Kaspersky's Global Research and Analysis Team have uncovered technical links between the supply chain attack on Axios, one of the world's most widely used JavaScript libraries, and previously documented campaigns associated with BlueNoroff, a financially motivated subgroup of the Lazarus Group, the company said.
Axios is one of the most widely used JavaScript HTTP client libraries, with over 100 million weekly downloads on npm, according to Kaspersky. In March 2026, attackers compromised the npm account of a lead Axios maintainer and used it to publish malicious versions of the package, the company said. Those versions introduced a hidden dependency called plain-crypto-js, which Kaspersky said wasn't used by the library itself but executed during installation through a postinstall script, downloading and deploying a cross-platform remote access trojan targeting macOS, Windows and Linux systems.
BlueNoroff is a financially motivated subgroup of the Lazarus Group known for targeting financial institutions and cryptocurrency platforms, Kaspersky said, with a history of sophisticated attacks aimed at stealing funds through social engineering and custom malware.
Sergey Lozhkin, Kaspersky's head of GReAT for the APAC and META regions, said the connection emerged during analysis of the attack. "During our analysis of the Axios supply chain attack, we identified technical overlaps with two previously documented campaigns of Bluenoroff: GhostCall and GhostHire," he said. GhostCall and GhostHire are BlueNoroff campaigns targeting high-value individuals in the crypto industry, according to Kaspersky, with GhostCall using social engineering to target executives and GhostHire disguising malware as job opportunities and coding tests aimed at blockchain developers.
The overlaps Kaspersky identified include similarities in the user agent, use of a distinctive module name string called "webT," and the targeting of Linux, macOS and Windows within a single attack. Researchers also identified a new version of the SyphonV2 loader and overlaps in infrastructure used across the campaigns, the company said.
Lozhkin cautioned that the findings point to a possible connection rather than confirmed attribution. "These similarities provide indicators of a possible connection to BlueNoroff, although technical overlaps alone do not constitute definitive attribution," he said, noting that threat actors can reuse malware components, infrastructure and techniques, and may deliberately adopt characteristics from other campaigns to obscure their identity.
Kaspersky said BlueNoroff has a global targeting footprint, with its recent GhostCall and GhostHire campaigns targeting Web3 and cryptocurrency organizations in India, Turkey, Australia and other countries across Europe and Asia.
To defend against such attacks, Kaspersky recommended organizations verify identities through alternative channels before opening files or links from trusted contacts, avoid running unverified scripts or commands, and adopt layered defenses including endpoint detection and response tools, managed detection and response services, and threat intelligence feeds to maintain visibility across the incident management lifecycle.
Axios is one of the most widely used JavaScript HTTP client libraries, with over 100 million weekly downloads on npm, according to Kaspersky. In March 2026, attackers compromised the npm account of a lead Axios maintainer and used it to publish malicious versions of the package, the company said. Those versions introduced a hidden dependency called plain-crypto-js, which Kaspersky said wasn't used by the library itself but executed during installation through a postinstall script, downloading and deploying a cross-platform remote access trojan targeting macOS, Windows and Linux systems.
BlueNoroff is a financially motivated subgroup of the Lazarus Group known for targeting financial institutions and cryptocurrency platforms, Kaspersky said, with a history of sophisticated attacks aimed at stealing funds through social engineering and custom malware.
Sergey Lozhkin, Kaspersky's head of GReAT for the APAC and META regions, said the connection emerged during analysis of the attack. "During our analysis of the Axios supply chain attack, we identified technical overlaps with two previously documented campaigns of Bluenoroff: GhostCall and GhostHire," he said. GhostCall and GhostHire are BlueNoroff campaigns targeting high-value individuals in the crypto industry, according to Kaspersky, with GhostCall using social engineering to target executives and GhostHire disguising malware as job opportunities and coding tests aimed at blockchain developers.
The overlaps Kaspersky identified include similarities in the user agent, use of a distinctive module name string called "webT," and the targeting of Linux, macOS and Windows within a single attack. Researchers also identified a new version of the SyphonV2 loader and overlaps in infrastructure used across the campaigns, the company said.
Lozhkin cautioned that the findings point to a possible connection rather than confirmed attribution. "These similarities provide indicators of a possible connection to BlueNoroff, although technical overlaps alone do not constitute definitive attribution," he said, noting that threat actors can reuse malware components, infrastructure and techniques, and may deliberately adopt characteristics from other campaigns to obscure their identity.
Kaspersky said BlueNoroff has a global targeting footprint, with its recent GhostCall and GhostHire campaigns targeting Web3 and cryptocurrency organizations in India, Turkey, Australia and other countries across Europe and Asia.
To defend against such attacks, Kaspersky recommended organizations verify identities through alternative channels before opening files or links from trusted contacts, avoid running unverified scripts or commands, and adopt layered defenses including endpoint detection and response tools, managed detection and response services, and threat intelligence feeds to maintain visibility across the incident management lifecycle.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




