AWS has attributed a series of npm supply chain attacks — targeting popular libraries including axios, debug, chalk, and typo-crypto — to a North Korean threat group known as Sapphire Sleet or BlueNoroff. The group socially engineered package maintainers, then pushed malicious updates that automatically executed on installation.
Axios alone sees over 100 million weekly downloads, and the debug and chalk attacks hit roughly 10% of cloud environments within just two hours. AWS CISO CJ Moses noted the typo-crypto compromise in March 2025 appears to have been a test run. Attackers are also now exploiting AI-hallucinated package names to expand their reach.
Source: Infosecurity Magazine