Home Content News Amazon Traces NPM Supply-Chain Hacks To North Korean Hacker Group

Amazon Traces NPM Supply-Chain Hacks To North Korean Hacker Group

0
2
Amazon Web Services
Amazon Web Services (AWS)

Amazon Threat Intelligence has linked widespread compromises of core open-source libraries to a coordinated campaign by North Korea-backed actors using social engineering and AI-assisted malware.

Amazon Threat Intelligence (ATI) assesses with medium confidence that a financially motivated DPRK-linked (Democratic People’s Republic of Korea) threat actor, known as Sapphire Sleet, Stardust Chollima, BlueNoroff, CageyChameleon, and Alluring Pisces, is behind a series of major Node Package Manager (NPM) supply-chain compromises.

While the March 2026 compromise of axios (over 100 million weekly downloads) was previously linked to this group, ATI’s new findings connect three earlier incidents, typo-crypto, debug, and chalk, to the same operational playbook. The campaign followed a progression starting in March 2025 with typo-crypto, where the actor placed a trojanized core.js file communicating with npmjs[.]store. The group escalated in September 2025 by breaching debug and chalk, which Wiz Research found impacted roughly 1 in 10 global cloud environments within two hours, before executing the axios breach in March 2026.

Instead of exploiting zero-day vulnerabilities, the actor obtained publisher rights by socially engineering trusted maintainers, then executed malicious payloads via automated post-install hooks. Amazon also observed the actor using generative AI to draft and obfuscate payloads, apply execution gating to evade sandboxes, and probe AI code-auditing systems. AWS framed these attacks within an accelerating post-XZ Utils (2024) trend where state-sponsored actors exploit the limited time and trust of volunteer maintainers to maximize downstream reach across corporate networks.

LEAVE A REPLY

Please enter your comment!
Please enter your name here