Minacce · 59 giorni fa
Non sono quattro incidenti separati. AWS descrive invece un playbook ripetibile che parte da una compromissione piccola, probabilmente provata in anticipo, e si allarga a package npm molto usati che eseguono codice da soli durante l’installazione. Il punto debole è la catena delle dipendenze: un update dall’aria normale può infettare il build prima ancora di essere esaminato.
AWS collega axios, debug, chalk e typo-crypto a Saphire Sleet con confidenza media, sulla base di TTP condivise, riuso di codice, post-install hooks e indicatori C2. Il compromesso di typo-crypto di marzo 2025 viene letto come una prova generale; i casi successivi hanno colpito package con portata molto più ampia, fino a oltre 100 milioni di download settimanali per axios e a circa il 10% degli ambienti cloud in una finestra di due ore per debug e chalk.
Per chi automatizza il rilascio delle dipendenze open source, il rischio non è il nome del package in sé. È il fatto che la fiducia nel maintainer e nel canale di update basta a far eseguire il payload prima di qualsiasi verifica umana, quindi una compromissione piccola può propagarsi in molti ambienti downstream insieme.
5 fonti che coprono questa storia
In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research
Noteworthy stories that might have slipped under the radar: parcel delivery company OnTrac hacked, Adobe patches, UK Department for Education loses 607,000 records.
AWS Blames North Korean Group for npm Supply Chain Attacks
AWS has linked North Korea to the axios campaign to other attacks on npm libraries
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers.
The Record from Recorded Future
North Korean hackers behind major open-source supply chain attacks, Amazon says
A North Korea-linked hacker group was behind several high-profile compromises of open-source software libraries used by developers worldwide, researchers have found.
Amazon is sharing new findings about how a threat actor linked to the Democratic People’s Republic of Korea (DPRK) is targeting open source software libraries, the shared building blocks that companies around the world use to develop applications.
Part of the PlainSec briefing for 2026-08-01