Skip to content
North Korean Hackers Target Open Source Software Supply Chain via npm Packages

North Korean Hackers Target Open Source Software Supply Chain via npm Packages

First seen 29 Jul 2026, 23:26 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 30, 2026 at 22:28 UTC
  • Four npm packages linked to North Korean hackers, affecting global software development.
  • Attackers used social engineering to compromise maintainers and inject malicious updates.
  • Generative AI is enhancing the sophistication of these supply chain attacks.

Amazon's threat intelligence has linked a series of compromises of popular npm packages—axios, debug, chalk, and typo-crypto—to a North Korean hacking group known as Sapphire Sleet. The group employed social engineering tactics to compromise maintainers' accounts, allowing them to publish malicious updates that affected numerous organizations globally. The axios package, which alone has over 100 million weekly downloads, was targeted in March 2026, following earlier compromises of the other packages in 2025. The attack vector involved injecting malicious dependencies that deployed backdoors across various operating systems. This coordinated campaign highlights a shift from direct intrusions to exploiting open-source software supply chains. Amazon's findings indicate that the threat actor's methods are evolving, aided by generative AI technologies. The scope of impact is significant, with estimates suggesting that 10% of cloud environments were affected by the debug and chalk incidents within hours of their compromise.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 51d ago How this analysis works

Timeline

2025-03-01
Typo-crypto package compromised
North Korean hackers injected malicious code into the typo-crypto package, marking the start of their campaign.
Cyberscoop
2025-09-01
Debug and Chalk packages compromised
The same threat actor compromised the debug and chalk packages, affecting cloud environments significantly.
BleepingComputer
2026-03-31
Axios package compromised
A malicious dependency was introduced into the axios package, impacting over 100 million downloads weekly.
Google Cloud
2026-07-29
Amazon publicly links attacks to Sapphire Sleet
Amazon's threat intelligence revealed connections between the four npm package compromises and the North Korean group Sapphire Sleet.
AWS Amazon
2026-07-30
Google confirms Axios attribution to Sapphire Sleet
Google Threat Intelligence confirmed the attribution of the axios compromise to the Sapphire Sleet group, detailing the attack lifecycle.
cloud.google.com

More articles in this cluster (13)

Following this threat?

Track Alluring Pisces, Sandclock and Amazon in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed