Amazon Traces NPM Supply Chain Attacks to North Korean Hackers

Amazon attributes a series of high-profile supply chain attacks targeting the NPM ecosystem to Sapphire Sleet, a North Korean threat actor also known as BlueNoroff. The campaign begins with the trojanizing of the typo-crypto package in March 2025 and escalates dramatically with the compromise of widely used packages like debug, chalk, and axios. Amazon links these incidents together through shared tactics, command-and-control infrastructure, and operational similarities.

The attackers gain access by socially engineering package maintainers before publishing malicious updates that automatically reach unsuspecting users. The financial motivation drives the targeting of extremely popular packages, allowing the hackers to reach a massive pool of downstream victims. The axios compromise alone affects a library with over 100 million weekly downloads, highlighting the scale of potential exposure.

Amazon identifies several troubling trends emerging from these attacks. Threat actors spend months building trust within open-source communities before introducing malicious code, and they split malicious functionality across multiple packages to evade detection. The payloads use stronger encryption, multi-stage delivery, and environment-aware execution that delays activation in analysis sandboxes, making these threats significantly harder to catch.

Read More at the original source →