s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-osx.waveshaper

📛 Threat Title

Malware family: WAVESHAPER

Category: WAVESHAPER First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.waveshaper`. Printable name: WAVESHAPER. Aliases: osx.curlyveiltea.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain osx.waveshaper VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.waveshaper

IOC database

Type
domain
Value
osx.waveshaper
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-osx.waveshaper

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.waveshaper

References (1)

Remediations (10)

  • web:cloud.google.com

    A North Korea-nexus threat actor targeted the popular axios NPM package in a massive supply chain attack.

  • web:coderoasis.com

    Axios — 100 million weekly npm downloads, used in practically every Node.js application on the planet — got hit twice in two weeks. On March 31, 2026, North Korean state actors hijacked the lead maintainer's npm account and deployed a cross-platform RAT through a malicious dependency.

  • web:cybersecuritynews.com

    The company linked the activity to UNC1069, a financially motivated North Korea-nexus threat actor, based on overlaps in infrastructure and the use of the updated WAVESHAPER .V2 malware family . What makes this campaign especially dangerous is its simple delivery method.

  • web:medium.com

    The attribution rests on two pillars: WAVESHAPER .V2 is an updated version of the WAVESHAPER malware family , which has been exclusively associated with UNC1069 in prior campaigns.

  • web:securityarsenal.com

    Malicious versions 1.14.1 and 0.30.4 of the Axios npm package delivered WAVESHAPER .V2 RAT. Immediate detection and isolation required.

  • web:tech-insider.org

    North Korean hackers hijacked the axios npm package with 100M weekly downloads, deploying WAVESHAPER .V2 malware in a 3-hour supply chain attack on March 31, 2026.

  • web:threatprotect.qualys.com

    A sophisticated supply-chain attack is targeting the popular npm package Axios. Attackers compromised a lead maintainer's account to publish malicious versions 1.14.1 and 0.30.4, injecting a hidden dependency called plain-crypto-js version 4.2.1. The dependency executes a postinstall script that acts as a cross-platform remote access trojan (RAT) dropper, targeting macOS, Windows, and Linux ...

  • web:www.invictus-ir.com

    ‍ The Wait-and-See Defense: In the Axios attack, scanners flagged the malware in just six minutes, but susceptibility is still introduced in the window between a malicious upload and its removal from the registry. A way to remediate this is by implementing a minimum release age.

  • web:www.microsoft.com

    Users should also follow the mitigation and protection guidance provided in this blog, including disabling auto-updates for Axios npm packages, since the malicious payload includes a hook that will continue to attempt to update.

  • web:www.sans.org

    Malware Family : WAVESHAPER .V2 (tracked by Google GTIG; attributed to UNC1069) Targets: GitHub PATs, AWS keys, Azure credentials, SSH keys, cloud tokens Additional IOCs will be published on the SANS blog as they are confirmed. Josh closed with something worth repeating. Incident response is a marathon, not a sprint.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.