Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers.
The cloud computing giant linked the compromises of the typo-crypto, debug, chalk, and axios libraries to the Sapphire Sleet threat actor, also known as BlueNoroff and Stardust Chollima.
Initial activity started with trojanizing the typo-crypto package in March 2025, which Amazon believes served as a testing ground. It then escalated in September of the same year with the compromise of the widely used debug and chalk packages, affecting an estimated 10% of cloud environments within two hours.
In March 2026, the hacker targeted axios, one of npm’s most popular packages with over 100 million weekly downloads.
It should be noted that the axios incident has already been publicly attributed to DPRK-linked actors, but Amazon connected it to the earlier package compromises.
Amazon says the attacker gained access by socially engineering package maintainers, and then published malicious updates that were automatically distributed to unsuspecting users.
The attribution to Sapphire Sleet has medium confidence and is based on the shared tactics, techniques, and procedures (TTPs) observed in the campaign, the command-and-control (C2) infrastructure, and various operational similarities.
Also, the researchers believe the attacker had a financial motivation, targeting popular packages to gain indirect access to a large pool of potential downstream victims at once.
Amazon also highlights several trends that have emerged from the recent supply-chain attacks:
Many of these tactics are enhanced and simplified by AI, Amazon explains, as they help attackers generate code, documentation, and maintainer identities.
Amazon highlighted a multi-faceted response to these dangers, including reporting its findings and intelligence to the community, collaborating with OpenSSF and other industry partners, and investing $12.5M in the Akrites initiative, which helps protect critical open-source software from AI-enabled attacks.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Hackers backdoor Jscrambler npm package with infostealer malware
Microsoft links Mastra AI supply chain attack to North Korean hackers
AsyncAPI npm packages infected with credential-stealing malware
Injective SDK on npm infected with cryptocurrency wallet stealer
GitHub announces npm security changes to tackle supply-chain attacks
Anthropic confirms Claude is down worldwide
OpenAI models used Artifactory zero-days to escape to the internet
Windows 11 KB5101684 update released with 42 changes and fixes
Your Scanners Are Green. Your Pipeline Might Not Be. Here’s How to Close the Gap.
Uncover shadow AI apps, agents, and risky data sharing. Get started in 5 min.
Overdue a password health-check? Audit your Active Directory for free
Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Download the case study for how.
Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday.
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



