<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

AWS Pins npm Supply Chain Attacks on North Korean Hackers

North Korean group Sapphire Sleet targets npm libraries like axios, debug, and chalk, exploiting AI-named packages to expand attacks.
Content Team

AWS has attributed a series of npm supply chain attacks — targeting popular libraries including axios, debug, chalk, and typo-crypto — to a North Korean threat group known as Sapphire Sleet or BlueNoroff. The group socially engineered package maintainers, then pushed malicious updates that automatically executed on installation.

Axios alone sees over 100 million weekly downloads, and the debug and chalk attacks hit roughly 10% of cloud environments within just two hours. AWS CISO CJ Moses noted the typo-crypto compromise in March 2025 appears to have been a test run. Attackers are also now exploiting AI-hallucinated package names to expand their reach.

Source: Infosecurity Magazine

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo