North KoreaCháoxiǎn朝鲜hackerhēikè黑客to breachrùqīn入侵open-sourcekāiyuán开源software toolgōngjù工具Axios (JavaScript library)AxiosAxios,hundreds of thousands ofshù shí wàn gè数十万个developerkāifā zhě开发者access credentialspíngzhèng凭证to facemiànlín面临leakage riskxièlòu泄露riskfēngxiǎn风险。
North Korea
Cháoxiǎn
朝鲜
hacker
hēikè
黑客
to breach
rùqīn
入侵
open-source
kāiyuán
开源
software tool
gōngjù
工具
Axios (JavaScript library)
Axios
Axios
hundreds of thousands of
shù shí wàn gè
数十万个
developer
kāifā zhě
开发者
access credentials
píngzhèng
凭证
to face
miànlín
面临
leakage risk
xièlòu
泄露
risk
fēngxiǎn
风险
linked with
yǔ
与
North Korea
Cháoxiǎn
朝鲜
associated with
yǒu guānlián de
有关联的
hacker
hēikè
黑客
breached
rùqīn le
入侵了
open-source
kāiyuán
开源
software tool
gōngjù
工具
Axios (JavaScript library)
Axios
Axios
and also
bìng
并
to implant
zhírù
植入
malicious
èyì
恶意
backdoor
hòumén
后门
code
dàimǎ
代码
Google
Gǔgē
谷歌
threat intelligence
wēixié qíngbào
威胁情报
team
tuánduì
团队
to warn
jǐnggào
警告
this incident
cǐ cì
此次
supply chain
gōngyìng liàn
供应链
attack
gōngjī
攻击
scope of impact
yǐngxiǎng fànwéi
影响范围
wide-ranging
guǎngfàn
广泛
possibly
kěnéng
可能
to spread to / affect
bōjí
波及
global
quánqiú
全球
hundreds of thousands of
shù shí wàn gè
数十万个
application / app
yìngyòng chéngxù
应用程序
April 1, 2026 at 10:00 PM
linked with
yǔ
与
North Korea
Cháoxiǎn
朝鲜
associated with
yǒu guānlián de
有关联的
hacker
hēikè
黑客
breached
rùqīn le
入侵了
widely used
guǎng shòu
广受
developer
kāifā zhě
开发者
used by
shǐyòng de
使用的
open-source
kāiyuán
开源
software
ruǎnjiàn
软件
tool
gōngjù
工具
Axios (JavaScript library)
Axios
Axios
and also
bìng
并
to implant
zhírù
植入
malicious
èyì
恶意
backdoor code
hòumén dàimǎ
后门代码
Axios (JavaScript library)
Axios
Axios
is
shì
是
a type of
yī kuǎn
一款
used for
yòngyú
用于
network requests
wǎngluò qǐngqiú
网络请求
structural particle
de
的
JavaScript (programming language)
JavaScript
JavaScript
tool
gōngjù
工具
every week
měi zhōu
每周
download volume
xiàzài liàng
下载量
exceeding
chāoguò
超过
tens of millions of times
shù qiān wàn cì
数千万次
passive marker
bèi
被
global
quánqiú
全球
numerous
zhòngduō
众多
enterprise / company
qǐyè
企业
and
hé
和
application / app
yìngyòng chéngxù
应用程序
widely adopted
guǎngfàn cǎiyòng
广泛采用
according to
jù
据
Google
Gǔgē
谷歌
threat intelligence
wēixié qíngbào
威胁情报
team
tuánduì
团队
analysis
fēnxī
分析
attacker
gōngjī zhě
攻击者
took control of
kòngzhì le
控制了
Axios (JavaScript library)
Axios
Axios
project
xiàngmù
项目
structural particle
de
的
one
yī gè
一个
maintenance
wéihù
维护
account
zhànghù
账户
subsequently
suíhòu
随后
published / released
fābù le
发布了
two
liǎng gè
两个
containing
hányǒu
含有
backdoor
hòumén
后门
structural particle
de
的
malicious version
èyì bǎnběn
恶意版本
these
zhèxiē
这些
malicious versions
èyì bǎnběn
恶意版本
can / able to
kěyǐ
可以
to steal
qièqǔ
窃取
user
yònghù
用户
device
shèbèi
设备
on the
shàng de
上的
access credentials
fǎngwèn píngzhèng
访问凭证
and
bìng
并
transmit them
jiāng qí
将其
send to
chuánsòng gěi
传送给
attacker
gōngjī zhě
攻击者
thereby
cóngér
从而
for
wèi
为
further
jìn yī bù de
进一步的
cyberattack
wǎngluò gōngjī
网络攻击
to create conditions
chuàngzào tiáojiàn
创造条件
Google
Gǔgē
谷歌
researchers
yánjiū rényuán
研究人员
to state
biǎoshì
表示
this
cǐ cì
此次
attack
gōngjī
攻击
scope of impact
yǐngxiǎng fànwéi
影响范围
wide-ranging
guǎngfàn
广泛
and
qiě
且
to possess
jùyǒu
具有
ripple effect
liánsuǒ xiàoyìng
连锁效应
possibly
kěnéng
可能
already
yǐ yǒu
已有
hundreds of thousands of
shù shí wàn gè
数十万个
credentials
píngzhèng
凭证
stolen / compromised
zāo qiè
遭窃
security expert
ānquán zhuānjiā
安全专家
to recommend
jiànyì
建议
all
suǒyǒu
所有
using
shǐyòng
使用
Axios (JavaScript library)
Axios
Axios
structural particle
de
的
developer
kāifā zhě
开发者
immediately
lìjí
立即
to check
jiǎnchá
检查
project
xiàngmù
项目
dependencies
yīlài xiàng
依赖项
and
bìng
并
to update to
gēngxīn zhì
更新至
official
guānfāng
官方
verified
yànzhèng de
验证的
safe / clean version
ānquán bǎnběn
安全版本
this
cǐ cì
此次
incident
shìjiàn
事件
once again
zàicì
再次
to trigger
yǐnfā
引发
the wider public
wàijiè
外界
regarding
duì
对
open-source software
kāiyuán ruǎnjiàn
开源软件
supply chain
gōngyìng liàn
供应链
security
ānquán
安全
structural particle
de
的
heightened attention
gāodù guānzhù
高度关注
News in English
Science & TechnologyNorth Korea-Linked Hackers Breach Axios Open-Source Library, Putting Hundreds of Thousands of Developer Credentials at Risk
North Korea-linked hackers breached the Axios open-source library, inserting malicious backdoor code. Google threat intelligence warned the supply chain attack could affect hundreds of thousands of applications worldwide.
More in Science & Technology
MicrosoftWēiruǎn微软and / withyǔ与OpenAI (AI company)OpenAIOpenAIto revise / to amendxiūɡǎi修改cooperation / partnershiphézuò合作agreement / termsxiéyì协议,to give up / to relinquishfànɡqì放弃exclusivedújiā独家license / authorizationshòuquán授权。
Microsoft
Wēiruǎn
微软
and / with
yǔ
与
OpenAI (AI company)
OpenAI
OpenAI
to revise / to amend
xiūɡǎi
修改
cooperation / partnership
hézuò
合作
agreement / terms
xiéyì
协议
to give up / to relinquish
fànɡqì
放弃
exclusive
dújiā
独家
license / authorization
shòuquán
授权
Microsoft and OpenAI Revise Partnership to End Exclusive Licensing Arrangement
Dell (company)Dài ěr戴尔first quarterdì yī jìdù第一季度AI (artificial intelligence)AIAIserverfúwùqì服务器revenueyínɡshōu营收year over yeartónɡbǐ同比to surge dramaticallybàozēnɡ暴增757 percent757%757%。
Dell (company)
Dài ěr
戴尔
first quarter
dì yī jìdù
第一季度
AI (artificial intelligence)
AI
AI
server
fúwùqì
服务器
revenue
yínɡshōu
营收
year over year
tónɡbǐ
同比
to surge dramatically
bàozēnɡ
暴增
757 percent
757%
757%
Dell AI Server Revenue Surges 757 Percent Year Over Year in Record Quarter
United KingdomYīngguó英国researchersyánjiū rényuán研究人员to obtain / to gain access tohuòdé获得GoogleGǔgē谷歌Willow (Google quantum chip)WillowWillowquantumliàngzǐ量子chipxīnpiàn芯片access rights / right to useshǐyòngquán使用权。
United Kingdom
Yīngguó
英国
researchers
yánjiū rényuán
研究人员
to obtain / to gain access to
huòdé
获得
Google
Gǔgē
谷歌
Willow (Google quantum chip)
Willow
Willow
quantum
liàngzǐ
量子
chip
xīnpiàn
芯片
access rights / right to use
shǐyòngquán
使用权
UK Researchers at Kings College London Gain Access to Google Willow Quantum Chip
United StatesMěiguó美国Illinois (US state)Yīlìnuòyī Zhōu伊利诺伊州to pass (legislation)tōngɡuò通过across the US / nationwidequánměi全美most stringent / strictestzuì yángé最严格AI (artificial intelligence)AIAIsafety / securityānquán安全bill / legislationfǎàn法案。
United States
Měiguó
美国
Illinois (US state)
Yīlìnuòyī Zhōu
伊利诺伊州
to pass (legislation)
tōngɡuò
通过
across the US / nationwide
quánměi
全美
most stringent / strictest
zuì yángé
最严格
AI (artificial intelligence)
AI
AI
safety / security
ānquán
安全
bill / legislation
fǎàn
法案
Illinois Passes Nation Most Stringent AI Safety Bill Requiring Third-Party Audits