Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

China-nexus and North Korean state-sponsored threat actors conducted sustained, coordinated campaigns against technology organizations from April 2025 through March 2026, targeting intellectual property, AI research, and developer supply chains. The most acute risk is the confirmed compromise of the Axios npm package (versions v1.14.1 and v0.30.4), which planted a remote access trojan inside one of the most widely deployed JavaScript libraries, exposing any organization that updated without integrity verification. Compounding state-actor activity, elevated access broker operations and ransomware activity in the technology sector signal a sustained threat environment requiring immediate supply chain audit and insider threat review.

Author

Tech Jacks Solutions