Cyberscoop
North Korean Hackers Target Open Source Software Supply Chain via npm Packages
Article Content
Amazon's threat intelligence has linked a series of compromises of popular npm packages—axios, debug, chalk, and typo-crypto—to a North Korean hacking group known as Sapphire Sleet. The group employed social engineering tactics to compromise maintainers' accounts, allowing them to publish malicious updates that affected numerous organizations globally. The axios package, which alone has over 100 million weekly downloads, was targeted in March 2026, following earlier compromises of the other packages in 2025. The attack vector involved injecting malicious dependencies that deployed backdoors across various operating systems. This coordinated campaign highlights a shift from direct intrusions to exploiting open-source software supply chains. Amazon's findings indicate that the threat actor's methods are evolving, aided by generative AI technologies. The scope of impact is significant, with estimates suggesting that 10% of cloud environments were affected by the debug and chalk incidents within hours of their compromise.
Key Points: • Four npm packages linked to North Korean hackers, affecting global software development. • Attackers used social engineering to compromise maintainers and inject malicious updates. • Generative AI is enhancing the sophistication of these supply chain attacks.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.