North Korean Hackers Behind Open Source Supply Chain Attacks
Amazon Web Services
Amazon's threat intelligence team linked a North Korean threat actor (SAPPHIRE SLEET) to compromises of popular NPM JavaScript libraries including axios, debug, chalk, and typo-crypto. The actor used social engineering to gain maintainer access and published malicious updates; the axios package alone has over 100 million weekly downloads, meaning the compromise affected numerous downstream environments simultaneously. Attackers are evolving techniques to split malicious behavior across multiple packages, accumulate trust over months, use stronger cryptography, and deploy payloads that avoid sandbox detection, while generative AI is enabling them to produce convincing code at scale.
Why it matters
Amazon identified a North Korean hacker group conducting open source supply chain attacks.