AWS Pins npm Supply Chain Attacks on North Korean Hackers
North Korean group Sapphire Sleet targets npm libraries like axios, debug, and chalk, exploiting AI-named packages to expand attacks.
By
Content Team
ON THIS PAGE
Want more insights like this?
Subscribe to our newsletter to get the latest software protection strategies delivered to your inbox.
By submitting your email, you consent to Codekeeper contacting you and agree to our privacy policy.
AWS has attributed a series of npm supply chain attacks — targeting popular libraries including axios, debug, chalk, and typo-crypto — to a North Korean threat group known as Sapphire Sleet or BlueNoroff. The group socially engineered package maintainers, then pushed malicious updates that automatically executed on installation.
Axios alone sees over 100 million weekly downloads, and the debug and chalk attacks hit roughly 10% of cloud environments within just two hours. AWS CISO CJ Moses noted the typo-crypto compromise in March 2025 appears to have been a test run. Attackers are also now exploiting AI-hallucinated package names to expand their reach.
Source: Infosecurity Magazine
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo