North Korean Hackers Target Open Source Software Supply Chain via npm Packages

North Korean Hackers Target Open Source Software Supply Chain via npm Packages

First seen 29 Jul 2026, 23:26 UTC Aws.AmazonCyberscoopWsjCybersecuritynewsGbhackers+8 86% similarity 77.1

Article Content

Browse articles
ThreatCluster

Amazon's threat intelligence has linked a series of compromises of popular npm packages—axios, debug, chalk, and typo-crypto—to a North Korean hacking group known as Sapphire Sleet. The group employed social engineering tactics to compromise maintainers' accounts, allowing them to publish malicious updates that affected numerous organizations globally. The axios package, which alone has over 100 million weekly downloads, was targeted in March 2026, following earlier compromises of the other packages in 2025. The attack vector involved injecting malicious dependencies that deployed backdoors across various operating systems. This coordinated campaign highlights a shift from direct intrusions to exploiting open-source software supply chains. Amazon's findings indicate that the threat actor's methods are evolving, aided by generative AI technologies. The scope of impact is significant, with estimates suggesting that 10% of cloud environments were affected by the debug and chalk incidents within hours of their compromise.

Key Points: • Four npm packages linked to North Korean hackers, affecting global software development. • Attackers used social engineering to compromise maintainers and inject malicious updates. • Generative AI is enhancing the sophistication of these supply chain attacks.

ThreatCluster AI How this analysis works

Timeline

2025-03-01
Typo-crypto package compromised
North Korean hackers injected malicious code into the typo-crypto package, marking the start of their campaign.
Cyberscoop
2025-09-01
Debug and Chalk packages compromised
The same threat actor compromised the debug and chalk packages, affecting cloud environments significantly.
BleepingComputer
2026-03-31
Axios package compromised
A malicious dependency was introduced into the axios package, impacting over 100 million downloads weekly.
Google Cloud
2026-07-29
Amazon publicly links attacks to Sapphire Sleet
Amazon's threat intelligence revealed connections between the four npm package compromises and the North Korean group Sapphire Sleet.
AWS Amazon
2026-07-30
Google confirms Axios attribution to Sapphire Sleet
Google Threat Intelligence confirmed the attribution of the axios compromise to the Sapphire Sleet group, detailing the attack lifecycle.
cloud.google.com

Community

Browse all →