Node.js A.I CyberSecurity Scoring
Node.js
Company Information
Website:http://nodejs.org
Employees number:16
Number of followers:832
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:nodejs.org
Node.js Risk Score (AI oriented)
Between 700 and 749
Node.jsTechnology, Information and Internet
Updated:
06/04/2026
06/04/2026
733/1000
Moderate
Ba
Node.js Global Score (TPRM)
xxxx
Node.jsTechnology, Information and Internet
Score locked

Node.jsModerate
Current Score
733Ba (MODERATE)
01000
1 incidents
-32 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
735
MAY 2026
734
APRIL 2026
765
Cyber Attack
31 Mar 2026 • Node.js
Platformatic, Axios and Node.js: North Korean Hackers Target High-Profile Node.js Maintainers
North Korean Hackers Target Node.js Maintainers in Sophisticated Supply Chain Attack
733
CRITICAL-32
NODOPEAXI1775479086
North Korean Hackers Target Node.js Maintainers in Sophisticated Supply Chain Attack
A North Korean threat group, UNC1069, has been linked to a social engineering campaign targeting high-profile Node.js maintainers, following a supply chain attack on Axios in late March. The attackers published two malicious NPM packages on March 31, which were downloaded by an estimated 3 million users before being removed within three hours.
The breach began when Axios lead maintainer Jason Saayman was infected with a backdoor after falling victim to a fake Microsoft Teams meeting. The attackers, posing as legitimate contacts, lured Saayman into installing a remote access trojan (RAT) under the guise of a required update. This tactic mirrors those used in previous campaigns, including DeceptiveDevelopment, Operation Dream Job, Contagious Interview, and ClickFake Interview.
The same group has since expanded its efforts, targeting multiple Node.js maintainers, including Socket CEO Feross Aboukhadijeh, Wes Todd (Node Package Maintenance Working Group), Matteo Collina (Platformatic), Scott Motte (Dotenv), and Ulises Gascón (Node.js Security Working Group). These individuals oversee hundreds of NPM packages with billions of downloads, making them prime targets for supply chain compromise.
The campaign, executed over several weeks, involved meticulous social engineering attackers built fake meeting infrastructure, established trust, and conducted themselves with professionalism to avoid suspicion. Socket noted that the operation was designed to appear routine, with attackers scheduling and rescheduling calls to blend in with legitimate business interactions.
In February, Google warned that UNC1069 had used similar tactics against DeFi companies, cryptocurrency firms, and venture capital entities. Security researchers have urged the open-source community to remain vigilant, as the group continues to refine its methods.
The Axios attack and subsequent targeting of Node.js maintainers highlight the growing threat of supply chain attacks orchestrated by state-backed actors, with potential for widespread disruption given the scale of the affected packages.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
MARCH 2026
765
FEBRUARY 2026
765
JANUARY 2026
765
DECEMBER 2025
765
NOVEMBER 2025
765
OCTOBER 2025
765
SEPTEMBER 2025
765
AUGUST 2025
765
JULY 2025
765
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Node.js ??
What was Node.js's A.I Rankiteo Cyber Score in May 2026 ??
What was Node.js's A.I Rankiteo Cyber Score in April 2026 ??
What was Node.js's A.I Rankiteo Cyber Score in March 2026 ??
What was Node.js's A.I Rankiteo Cyber Score in February 2026 ??
What was Node.js's A.I Rankiteo Cyber Score in January 2026 ??
What was Node.js's A.I Rankiteo Cyber Score in December 2025 ??
What was Node.js's A.I Rankiteo Cyber Score in November 2025 ??
What was Node.js's A.I Rankiteo Cyber Score in October 2025 ??
What was Node.js's A.I Rankiteo Cyber Score in September 2025 ??
What was Node.js's A.I Rankiteo Cyber Score in August 2025 ??
What was Node.js's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Node.js's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Node.js ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Node.js's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?