The break is the install step. A trusted-looking npm update can run code before anyone reviews it, so a clean package name does not stop a compromised dependency from reaching build systems and cloud environments. AWS now says this was not four separate incidents but one repeatable playbook tied with medium confidence to DPRK-linked Saphire Sleet.
AWS links axios, debug, chalk, and typo-crypto through shared TTPs, code reuse, post-install hooks, and C2 indicators. It says the March typo-crypto compromise was likely a test run before the later campaigns hit far wider targets, including axios at more than 100 million weekly downloads and debug/chalk activity that touched about 10% of cloud environments in a two-hour window.
The practical risk is not just a bad package. Any pipeline that auto-installs open-source dependencies can be reached through the same maintainer-trust path, and the malicious code can execute before routine review catches the update.
In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research
Noteworthy stories that might have slipped under the radar: parcel delivery company OnTrac hacked, Adobe patches, UK Department for Education loses 607,000 records.
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers.