{"id":13450,"date":"2026-04-05T12:50:45","date_gmt":"2026-04-05T12:50:45","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=13450"},"modified":"2026-04-05T12:50:45","modified_gmt":"2026-04-05T12:50:45","slug":"unc1069-targets-node-js-maintainers-by-way-of-pretend-linkedin-slack-profiles","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=13450","title":{"rendered":"UNC1069 Targets Node.js Maintainers by way of Pretend LinkedIn, Slack Profiles"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>A coordinated group of hackers is at the moment focusing on Open Supply Maintainers, significantly these managing Node.js and npm, following a high-profile assault on the favored <a rel=\"nofollow\" target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/hackers-poison-axios-npm-package-100m-downloads\/\">Axios<\/a> npm package deal. <\/p>\n<p>Safety consultants at Socket investigated these assaults, figuring out that hackers are utilizing social engineering strategies to provoke contact by LinkedIn or Slack, posing as recruiters or podcast hosts beneath pretend firm profiles and utilizing pretend assembly websites that look precisely like <a rel=\"nofollow\" target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/microsoft-teams-guest-chat-flaw-malware\/\" data-type=\"link\" data-id=\"https:\/\/hackread.com\/microsoft-teams-guest-chat-flaw-malware\/\">Microsoft Groups<\/a> or Zoom.<\/p>\n<h3 id=\"how-the-trick-works\" class=\"wp-block-heading\"><strong>How the Trick Works<\/strong><\/h3>\n<p>In accordance with Socket\u2019s analysis, these scammers are very affected person, as they spend weeks constructing rapport earlier than sending the suspicious hyperlink. For instance, on 5 March 2026, a developer named Jean Burellier was contacted on LinkedIn by somebody posing as a consultant of Openfort, and wasn\u2019t invited to a name till twenty third March, by way of a pretend hyperlink that gave the impression to be <code>groups.microsoft.com<\/code> however redirected to a copycat website, <code>groups.onlivemeet.com<\/code>.<\/p>\n<p>Through the name, they fake there&#8217;s a technical glitch and ask the professional to obtain a small repair. This file is definitely a distant entry trojan (<a rel=\"nofollow\" target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/xworm-7-1-remcos-rat-windows-tools-evade-detection\/\" data-type=\"post\" data-id=\"142568\">RAT<\/a>), which supplies hackers whole management over the sufferer\u2019s pc. The attackers\u2019 final objective is to steal the maintainer\u2019s credentials to realize \u201cwrite entry\u201d to their tasks, to push malicious code immediately into the official software program updates<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a rel=\"nofollow\" target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/wp-content\/uploads\/2026\/04\/UNC1069-Targets-Node.js-Maintainers-via-Fake-LinkedIn-and-Slack-Profiles.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"726\" src=\"https:\/\/hackread.com\/wp-content\/uploads\/2026\/04\/UNC1069-Targets-Node.js-Maintainers-via-Fake-LinkedIn-and-Slack-Profiles-1024x726.png\" alt=\"UNC1069 Targets Node.js Maintainers via Fake LinkedIn and Slack Profiles\" class=\"wp-image-143453\" srcset=\"https:\/\/hackread.com\/wp-content\/uploads\/2026\/04\/UNC1069-Targets-Node.js-Maintainers-via-Fake-LinkedIn-and-Slack-Profiles-1024x726.png 1024w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/04\/UNC1069-Targets-Node.js-Maintainers-via-Fake-LinkedIn-and-Slack-Profiles-300x213.png 300w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/04\/UNC1069-Targets-Node.js-Maintainers-via-Fake-LinkedIn-and-Slack-Profiles-768x545.png 768w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/04\/UNC1069-Targets-Node.js-Maintainers-via-Fake-LinkedIn-and-Slack-Profiles-1536x1090.png 1536w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/04\/UNC1069-Targets-Node.js-Maintainers-via-Fake-LinkedIn-and-Slack-Profiles-2048x1453.png 2048w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/04\/UNC1069-Targets-Node.js-Maintainers-via-Fake-LinkedIn-and-Slack-Profiles-380x270.png 380w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/04\/UNC1069-Targets-Node.js-Maintainers-via-Fake-LinkedIn-and-Slack-Profiles-800x568.png 800w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/04\/UNC1069-Targets-Node.js-Maintainers-via-Fake-LinkedIn-and-Slack-Profiles-1160x823.png 1160w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/04\/UNC1069-Targets-Node.js-Maintainers-via-Fake-LinkedIn-and-Slack-Profiles.png 2402w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\"\/><\/a><figcaption class=\"wp-element-caption\">Screenshots by way of Socket<\/figcaption><\/figure>\n<\/div>\n<p>\u201cThere\u2019s A LOT main as much as the decision. It\u2019s not pressing, urgent, or suspicious in any respect. It\u2019s not a one-click, get phished. They\u2019ll schedule a name for subsequent week after which reschedule it for the week after. It\u2019s loopy disarming,\u201d Socket\u2019s safety researcher Tay (@tayvano_) defined.<\/p>\n<h3 id=\"key-targets\" class=\"wp-block-heading\"><strong>Key Targets<\/strong><\/h3>\n<p>The attackers used a spoofed Streamyard platform to <a rel=\"nofollow\" target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/www.linkedin.com\/posts\/pellew_axios-maintainer-confirms-the-npm-compromise-activity-7445584047663247360-Eu6Y\/\" data-type=\"link\" data-id=\"https:\/\/www.linkedin.com\/posts\/pellew_axios-maintainer-confirms-the-npm-compromise-activity-7445584047663247360-Eu6Y\/\">trick Pelle Wessman<\/a>, a maintainer of Mocha, into downloading a virus. One other professional, Matteo Collina, almost fell for a Slack message on 2 April, whereas others like Scott Motte (creator of dotenv) and John-David Dalton (creator of Lodash) have been additionally focused. They even went after Socket CEO Feross Aboukhadijeh, the creator of WebTorrent and buffer, who famous that one of these focusing on is changing into the \u201cnew regular.\u201d<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"\/>\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">I\u2019ve simply realized extra particulars concerning the axios hack and\u2026 they tried to hack me too! Didn\u2019t work, however gosh.<\/p>\n<p>\u2014 Matteo Collina (@matteocollina) <a rel=\"nofollow\" target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/twitter.com\/matteocollina\/status\/2039808254356644004?ref_src=twsrc%5Etfw\">April 2, 2026<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<h3 id=\"a-new-level-of-danger\" class=\"wp-block-heading\"><strong>A New Stage of Hazard<\/strong><\/h3>\n<p>It is a difficult scenario as a result of whereas most of us assume two-factor authentication (2FA) is sufficient, researchers defined {that a} hacker can bypass these safety steps completely by acquiring deep entry utilizing instruments like WAVESHAPER or HYPERCALL.<\/p>\n<p>Behind this chaos is a financially motivated North Korean group, UNC1069. Google has <a rel=\"nofollow\" target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/north-korea-threat-actor-targets-axios-npm-package\" data-type=\"link\" data-id=\"http:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/north-korea-threat-actor-targets-axios-npm-package\">formally blamed<\/a> UNC1069 for the current Axios assault, noting that it&#8217;s a cluster of hackers with \u201cdeep expertise with provide chain assaults.\u201d<\/p>\n<p>As per Socket\u2019s analysis, UNC1069 shouldn&#8217;t be chasing particular person victims anymore, as they&#8217;ve probably realised that compromising only one one that manages a well-liked software permits them to robotically attain tens of millions of customers directly.<\/p>\n<p>Whereas consultants are the targets, it\u2019s the on a regular basis customers who find yourself with the malware. Due to this fact, maintainers needs to be cautious of any invite requiring software program installs, whereas the remainder of us should hold our techniques up to date to remain protected.<\/p>\n<p>\n\t\t\t<\/div>\n<p><template id="q40dLCcHmwyRrju9rCjF"></template><\/script><template id="5wNaNtBSLTtZva8Y6bhN"></template><\/script><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A coordinated group of hackers is at the moment focusing on Open Supply Maintainers, significantly these managing Node.js and npm, following a high-profile assault on the favored Axios npm package deal. Safety consultants at Socket investigated these assaults, figuring out that hackers are utilizing social engineering strategies to provoke contact by LinkedIn or Slack, posing [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":13452,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[67,7451,8530,3483,7840,8531,303,8529],"class_list":["post-13450","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-fake","tag-linkedin","tag-maintainers","tag-node-js","tag-profiles","tag-slack","tag-targets","tag-unc1069"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/13450","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=13450"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/13450\/revisions"}],"predecessor-version":[{"id":13451,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/13450\/revisions\/13451"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/13452"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=13450"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=13450"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=13450"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-05-27 05:44:18 UTC -->