Threats · 45 days ago
The break is the install step. A trusted-looking npm update can run code before anyone reviews it, so a clean package name does not stop a compromised dependency from reaching build systems and cloud environments. AWS now says this was not four separate incidents but one repeatable playbook tied with medium confidence to DPRK-linked Saphire Sleet.
AWS links axios, debug, chalk, and typo-crypto through shared TTPs, code reuse, post-install hooks, and C2 indicators. It says the March typo-crypto compromise was likely a test run before the later campaigns hit far wider targets, including axios at more than 100 million weekly downloads and debug/chalk activity that touched about 10% of cloud environments in a two-hour window.
The practical risk is not just a bad package. Any pipeline that auto-installs open-source dependencies can be reached through the same maintainer-trust path, and the malicious code can execute before routine review catches the update.
5 sources covering this story
In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research
Noteworthy stories that might have slipped under the radar: parcel delivery company OnTrac hacked, Adobe patches, UK Department for Education loses 607,000 records.
AWS Blames North Korean Group for npm Supply Chain Attacks
AWS has linked North Korea to the axios campaign to other attacks on npm libraries
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers.
The Record from Recorded Future
North Korean hackers behind major open-source supply chain attacks, Amazon says
A North Korea-linked hacker group was behind several high-profile compromises of open-source software libraries used by developers worldwide, researchers have found.
Amazon is sharing new findings about how a threat actor linked to the Democratic People’s Republic of Korea (DPRK) is targeting open source software libraries, the shared building blocks that companies around the world use to develop applications.
Part of the PlainSec briefing for 2026-08-01