Amazon's threat intelligence team attributed a series of high-profile compromises of Node Package Manager (npm) libraries—including axios, debug, chalk, and typo-crypt—to a North Korean hacker group called SapphireSleet. The discovery represents a significant supply-chain attack targeting widely-used open-source dependencies.
9 reportsother · tech
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
Amazon Traces NPM Supply-Chain Hacks To North Korean Hacker Group https://www.europesays.com/3162672/ Amazon Threat Intelligence has linked widespread compromises of core open-source libraries to a coordinated campaign by North Korea-backed… Amazon Threat Intelligence has linked widespread compromises of core open-source libraries to a coordinated campaign by North Korea-backed actors using social
Amazon Threat Intelligence has linked a North Korean hacker group to recent compromises of popular Node Package Manager (NPM) libraries, including axios, debug, chalk, and typo-crypto. The group, tracked as SAPPHIRE SLEET and others, employed social engineering to insert malicious code into updates.
North Korean hackers expand open-source software supply chain attacks: Amazon https://www.byteseu.com/2240016/ North Korean hackers expand open-source software supply chain attacks: Amazon Researchers link DPRK group to attacks on four popular JavaScript libraries underpinning software … Researchers link DPRK group to attacks on four popular JavaScript libraries underpinning software development w
Amazon Threat Intelligence said a North Korea-linked group known as Sapphire Sleet was behind four open-source software supply-chain compromises affecting npm packages used in JavaScript development: typo-crypto in March 2025, debug and chalk in September 2025, and axios in March 2026 [bleepingcomputer.com#1][therecord.media#1][thehackernews.com#1][computerweekly.com#1][developer-tech.com#1][there
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers https://www. bleepingcomputer.com/news/secu rity/amazon-links-debug-chalk-npm-supply-chain-attacks-to-north-korean-hackers/?utm_source=dlvr.it&utm_medium=%5Binfosec.exchange%5D