<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

North Korea Used Obscure npm Package as a Dress Rehearsal Before the Axios Hack

North Korean hackers used typo-crypto as a trial run before targeting axios, affecting 1 in 10 cloud environments in just hours.
Content Team

Amazon's security team has revealed that a North Korean hacking group — tracked as UNC1069, Sapphire Sleet, and Stardust Chollima — quietly compromised a small npm package called typo-crypto in March 2025, a full year before attacking axios, one of the internet's most downloaded libraries at 100 million weekly downloads.

Amazon CISO CJ Moses called typo-crypto a "rehearsal" — a low-profile test run to refine the group's methods before hitting bigger targets. The attackers didn't break in; they earned the trust of package maintainers and slipped malicious code into legitimate updates. Two other packages, debug and chalk, were also hit in September 2025. Wiz found roughly 1 in 10 cloud environments were affected within just two hours.

Source: CyberScoop

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo