Operative applied coercive pressure on Drug Enforcement in Chad [6 sources]
Published
Apr 24, 2026, 12:00 AM UTC
19d ago
Significance
Google Threat Intelligence reports a sophisticated supply chain attack on axios NPM package versions 1.14.1 and 0.30.4 (March 31, 2026), where attackers injected malicious 'plain-crypto-js' dependency to deploy WAVESHAPER.V2 backdoor across Windows, macOS, and Linux platforms. Attribution to UNC1069 based on malware signatures, infrastructure overlaps, and operational patterns. Remediation guidance includes version pinning, dependency auditing, CI/CD pipeline security, and credential rotation.
Srinagar reported tensions with Operative [10 sources]
Bandit reported tensions with Operative in Kyara [10 sources]
b9ebf4e9…openwatch.io →Operative reported tensions with Police Force in Kashmir [5 sources]