TF-MAL-osx.waveshaper
📛 Threat Title
Malware family: WAVESHAPER
Description
ThreatFox malware family `osx.waveshaper`. Printable name: WAVESHAPER. Aliases: osx.curlyveiltea.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.waveshaper
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.waveshaper
IOC database
- Type
- domain
- Value
osx.waveshaper- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.waveshaper
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.waveshaper
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cloud.google.com
A North Korea-nexus threat actor targeted the popular axios NPM package in a massive supply chain attack.
-
web:coderoasis.com
Axios — 100 million weekly npm downloads, used in practically every Node.js application on the planet — got hit twice in two weeks. On March 31, 2026, North Korean state actors hijacked the lead maintainer's npm account and deployed a cross-platform RAT through a malicious dependency.
-
web:cybersecuritynews.com
The company linked the activity to UNC1069, a financially motivated North Korea-nexus threat actor, based on overlaps in infrastructure and the use of the updated WAVESHAPER .V2 malware family . What makes this campaign especially dangerous is its simple delivery method.
-
web:medium.com
The attribution rests on two pillars: WAVESHAPER .V2 is an updated version of the WAVESHAPER malware family , which has been exclusively associated with UNC1069 in prior campaigns.
-
web:securityarsenal.com
Malicious versions 1.14.1 and 0.30.4 of the Axios npm package delivered WAVESHAPER .V2 RAT. Immediate detection and isolation required.
-
web:tech-insider.org
North Korean hackers hijacked the axios npm package with 100M weekly downloads, deploying WAVESHAPER .V2 malware in a 3-hour supply chain attack on March 31, 2026.
-
web:threatprotect.qualys.com
A sophisticated supply-chain attack is targeting the popular npm package Axios. Attackers compromised a lead maintainer's account to publish malicious versions 1.14.1 and 0.30.4, injecting a hidden dependency called plain-crypto-js version 4.2.1. The dependency executes a postinstall script that acts as a cross-platform remote access trojan (RAT) dropper, targeting macOS, Windows, and Linux ...
-
web:www.invictus-ir.com
The Wait-and-See Defense: In the Axios attack, scanners flagged the malware in just six minutes, but susceptibility is still introduced in the window between a malicious upload and its removal from the registry. A way to remediate this is by implementing a minimum release age.
-
web:www.microsoft.com
Users should also follow the mitigation and protection guidance provided in this blog, including disabling auto-updates for Axios npm packages, since the malicious payload includes a hook that will continue to attempt to update.
-
web:www.sans.org
Malware Family : WAVESHAPER .V2 (tracked by Google GTIG; attributed to UNC1069) Targets: GitHub PATs, AWS keys, Azure credentials, SSH keys, cloud tokens Additional IOCs will be published on the SANS blog as they are confirmed. Josh closed with something worth repeating. Incident response is a marathon, not a sprint.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.