Amazon Links North Korean Hackers to Surge in Open Source Attacks
Amazon's threat intelligence team has linked a North Korean hacking group to multiple recent attacks on popular open source software libraries, exploiting trust to compromise widely used packages with convincing malware. The group, tracked under various names, has targeted axios, debug, chalk, and typo-crypto packages with over 100 million weekly downloads.
Key points
- Amazon has linked a North Korean threat actor, tracked as SAPPHIRE SLEET, STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, and Alluring Pisces, to multiple recent compromises of popular NPM software libraries.
- The group exploited trust to compromise widely used packages, including axios, debug, chalk, and typo-crypto, with over 100 million weekly downloads.
- Attackers socially engineered a trusted maintainer before publishing a malicious software update in each case.
- Any organization that automatically pulled the latest version of these packages received the compromised code without warning.
- The compromised packages were used in attacks starting from March 2025, with the most recent attack targeting axios in March 2026.
Amazon's threat intelligence team has made a significant discovery, linking a North Korean hacking group to multiple recent attacks on popular open source software libraries. The group, tracked under various names, has exploited trust to compromise widely used packages with convincing malware.
The compromised packages, including axios, debug, chalk, and typo-crypto, have over 100 million weekly downloads, making them a prime target for attackers. In each case, attackers socially engineered a trusted maintainer before publishing a malicious software update.
The compromised packages were used in attacks starting from March 2025, with the most recent attack targeting axios in March 2026. Any organization that automatically pulled the latest version of these packages received the compromised code without warning.
This discovery highlights the importance of secure software development practices and the need for organizations to be vigilant in monitoring their software supply chains.
Sources
The WireByte editorial team synthesises technology news from multiple primary sources, verifies the facts, and links every source. Articles are produced with AI assistance and reviewed under our editorial policy.