WAVESHAPER.V2 is a cross-platform remote access trojan and backdoor associated with the North Korea-linked threat cluster UNC1069, also tracked in overlapping reporting with Sapphire Sleet. It is assessed to be an updated evolution of the earlier WAVESHAPER malware previously used in operations targeting the cryptocurrency sector. The malware has been observed in software supply chain intrusions, most notably through trojanized npm packages, where a malicious dependency executed during installation and deployed platform-specific payloads for Windows, macOS, and Linux.
WAVESHAPER.V2 is described as a fully functional RAT with reconnaissance, command execution, and file system enumeration capabilities. It collects host telemetry such as system identity, operating system details, boot time, time zone, and running process information; enumerates directories recursively and returns metadata; executes arbitrary shell commands; and supports in-memory Portable Executable injection on Windows. It can also retrieve and launch additional payloads, making it suitable for follow-on intrusion activity and broader post-compromise operations.
Platform-specific implementations have been reported in multiple languages, including a native C++ variant for macOS, a PowerShell-based variant for Windows, and a Python-based variant for Linux. Command-and-control communications use a JSON-based protocol and periodic polling behavior. On Windows, reported variants can establish persistence through autorun mechanisms, distinguishing the newer family from earlier WAVESHAPER tradecraft while retaining lineage traits such as dynamic receipt of command-and-control parameters and similar polling behavior.
WAVESHAPER.V2 has been linked to campaigns involving maintainer-account compromise and social engineering against trusted software publishers, enabling distribution through poisoned open-source packages with broad downstream exposure across developer workstations, CI/CD systems, and enterprise environments. Its use in supply chain attacks against widely deployed software components makes it notable both for initial compromise at scale and for enabling subsequent credential theft, lateral intrusion, and financially motivated operations aligned with UNC1069’s historical targeting patterns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Google attributed that incident to the cluster it tracks as UNC1069, citing malware known as WAVESHAPER.V2 together with infrastructure previously associated with the group.
Google attributed that incident to the cluster it tracks as UNC1069, citing malware known as WAVESHAPER.V2 together with infrastructure previously associated with the group.
Google independently attributed axios to UNC1069, citing the WAVESHAPER.V2 backdoor and an AstrillVPN node the group had used before.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Each wave used credentials stolen in a previous wave. Trivy tokens funded the npm wave. npm tokens funded LiteLLM. LiteLLM tokens funded Telnyx.
capable of... command execution... and arbitrary shell commands
The shell execution command expects a script and script parameters from C2; if no script is provided, the parameter is executed as a PowerShell command...
Command Execution: Supports multiple execution methods, including in-memory Portable Executable (PE) injection and arbitrary shell commands.
macOS: Downloads a C++ Mach-O binary, stores it in /Library/Caches/com.apple.act.mond, and executes it via /bin/zsh.
Windows: Copies PowerShell to %PROGRAMDATA%\wt.exe, disguising it as Windows Terminal, and executes a secondary script via VBScript with registry-based persistence.
Linux: Retrieves a Python-based implant to /tmp/ld.py and executes it in the background using nohup.
capable of... command execution (in-memory Portable Executable injection and arbitrary shell commands)
a malicious dependency named "plain-crypto-js", an obfuscated dropper that deploys the WAVESHAPER.V2 backdoor
Do knižnice Axios ju pridali ako falošnú závislosť, ktorá imituje legitímnu crypto-js@4.2.0.
capable of... command execution (in-memory Portable Executable injection and arbitrary shell commands)
Within seconds of execution, the dropper deletes the setup script, removes the postinstall hook, and replaces modified package files with benign decoys.
Each wave used credentials stolen in a previous wave. Trivy tokens funded the npm wave. npm tokens funded LiteLLM. LiteLLM tokens funded Telnyx.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware cited in attribution of the March 2026 axios compromise; associated with infrastructure tied to the actor and used as part of the supply-chain intrusion chain.
A backdoor cited by Google as part of the evidence used to attribute the axios npm compromise to UNC1069.
Cross-platform remote access trojan/backdoor deployed via the malicious npm dependency plain-crypto-js in compromised Axios releases, enabling remote access to infected systems and exfiltration of sensitive data.
A cross-platform backdoor delivered via the malicious plain-crypto-js dependency in poisoned Axios package versions, capable of infecting Windows, macOS, and Linux systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.