Amazon has attributed a wave of supply chain attacks on the npm ecosystem to a North Korean hacking group. The cloud provider’s security researchers linked compromises of several high-profile packages to Sapphire Sleet, a threat actor also known as BlueNoroff or Stardust Chollima.
The campaign began in March 2025 with a trojanized version of the typo-crypto package, which Amazon believes was used to test the attack method. In September 2025, the attackers escalated by compromising the widely adopted debug and chalk libraries. Within two hours, malicious updates had reached an estimated 10% of cloud environments, according to Amazon.
By March 2026, the group targeted axios—one of npm’s most popular packages, downloaded over 100 million times per week. While the axios incident had already been publicly associated with DPRK-linked actors, Amazon has now connected it to the earlier package compromises.
The attacker’s method involved socially engineering package maintainers to gain access, then pushing malicious updates that were automatically distributed to unsuspecting users. Amazon says the threat actor likely had financial motives, as compromising popular packages gave indirect access to a large pool of downstream victims.
Attribution to Sapphire Sleet is at medium confidence and relies on shared tactics, techniques, and procedures (TTPs), command-and-control infrastructure, and operational similarities across the incidents.
Amazon also outlined several trends emerging from these attacks, noting that AI tools are increasingly used to generate code, documentation, and even synthetic maintainer identities, making such campaigns simpler and more effective.
In response, the company has shared its findings and intelligence with the community, collaborated with OpenSSF and other industry partners, and invested $12.5 million in the Akrites initiative. This program aims to protect critical open-source software from AI-enabled attacks.
See an error? Read our corrections policy or email [email protected].
TECHNOMALIST