The North Korean threat actor behind the Axios supply chain attack has been targeting high-profile Node.js maintainers.
"The C2 hosts a web-based graphical user interface (GUI) titled 'NEXUS Listener' that can be used to view stolen information ...