North Korea Used Obscure npm Package as a Dress Rehearsal Before the Axios Hack
Want more insights like this?
Amazon's security team has revealed that a North Korean hacking group — tracked as UNC1069, Sapphire Sleet, and Stardust Chollima — quietly compromised a small npm package called typo-crypto in March 2025, a full year before attacking axios, one of the internet's most downloaded libraries at 100 million weekly downloads.
Amazon CISO CJ Moses called typo-crypto a "rehearsal" — a low-profile test run to refine the group's methods before hitting bigger targets. The attackers didn't break in; they earned the trust of package maintainers and slipped malicious code into legitimate updates. Two other packages, debug and chalk, were also hit in September 2025. Wiz found roughly 1 in 10 cloud environments were affected within just two hours.
Source: CyberScoop