Amazon identifies North Korean hackers as the perpetrators of a supply chain attack that compromised four npm packages.



On July 29, 2026, Amazon Threat Intelligence, Amazon's security team, reported that four supply chain attacks targeting open-source software that occurred between March 2025 and March 2026 were carried out by the North Korean hacker group 'SAPPHIRE SLEET.'

Amazon identifies North Korean hacker group behind open-source supply chain attacks | AWS Security Blog
https://aws.amazon.com/jp/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks/

Amazon links four poisoned npm packages to one North Korean crew
https://www.theregister.com/cyber-crime/2026/07/30/amazon-links-four-poisoned-npm-packages-to-one-north-korean-crew/5281120

Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
https://www.bleepingcomputer.com/news/security/amazon-links-debug-chalk-npm-supply-chain-attacks-to-north-korean-hackers/

Amazon Threat Intelligence has identified four open-source software compromises—'typo-crypto,' 'debug,' 'chalk,' and 'axios'—as being the work of the North Korean hacker group SAPPHIRE SLEET.

The initial breach occurred in March 2025, starting with the Trojanization of the typo-crypto npm package. Amazon Threat Intelligence believes this relatively small-scale attack was a test run for a larger-scale supply chain attack.

Subsequently, in September 2025, the more widely used debug and chalk npm packages were compromised, and it is estimated that approximately 10% of cloud environments were affected in just two hours.

18 popular npm packages with a combined weekly download count of over 2.6 billion may have been injected with malware; npm developer accounts were hacked, causing a major uproar - GIGAZINE



Then, in March 2026, axios, one of the most popular packages on npm with over 100 million downloads per week, became the target. Google had already linked the axios attack to North Korean hackers, but Amazon Threat Intelligence identified it as being carried out by the same group responsible for previous supply chain attacks.

Google identifies North Korean hacker group 'UNC1069' as the perpetrators of a supply chain attack against the open-source Axios - GIGAZINE



Based on common tactics and techniques observed in the series of supply chain attacks, such as Trojanized npm packages, scripts executed after npm package installation, and code reuse, as well as the execution procedures, Amazon Threat Intelligence has concluded with 'moderate confidence' that the attacks were carried out by SAPPHIRE SLEET.

SAPPHIRE SLEET is a hacker group also known by names such as STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, and Alluring Pisces, and their series of attacks are believed to be financially motivated. By targeting popular npm packages, they can indirectly access a large number of potential victims at once.

According to Amazon Threat Intelligence, the hackers did not exploit zero-day vulnerabilities or hack npm itself, but rather befriended software developers, gained their trust, and then released malicious updates from a 'highly trusted account' after obtaining access.

These attack methods are known as social engineering , where hackers reportedly spend months building trust by maintaining or contributing to legitimate projects before introducing malicious code. Amazon Threat Intelligence states, 'In each case, the attackers treated legitimacy as an asset that could only be used once at the moment of peak access.'

Amazon Threat Intelligence also warned that generative AI makes it easier for attackers to create trustworthy developer personas, send personalized messages to individual users, and sustain compelling social engineering campaigns over the long term. 'Attackers can now generate thousands of lines of consistent, idiomatic, and well-commented code with compelling documentation, plausible commit history, and fake maintainer IDs, and plant backdoors,' it pointed out.

in AI,   Software,   Security, Posted by log1h_ik