Amazon links North Korean hackers to npm supply-chain attacks

Amazon's threat intelligence team attributed a series of high-profile compromises of Node Package Manager (npm) libraries—including axios, debug, chalk, and typo-crypt—to a North Korean hacker group called SapphireSleet. The discovery represents a significant supply-chain attack targeting widely-used open-source dependencies.

9 reportsother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

"Amazon identifies North Korean hacker group behind open-source supply chain attacks" published by Amazon. # SupplyChain , # NPM , # SapphireSleet , # Axios https:// aws.amazon.com/blogs/security/ ama

mastodon:infosec-exchangeother62d ago kagi ↗

"Amazon identifies North Korean hacker group behind open-source supply chain attacks" published by Amazon. # SupplyChain , # NPM , # SapphireSleet , # Axios https:// aws.amazon.com/blogs/security/ amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks

Amazon Traces NPM Supply-Chain Hacks To North Korean Hacker Group - EUROPE SAYS

stream:bsky-jetstreamother61d ago kagi ↗

Amazon Traces NPM Supply-Chain Hacks To North Korean Hacker Group https://www.europesays.com/3162672/ Amazon Threat Intelligence has linked widespread compromises of core open-source libraries to a coordinated campaign by North Korea-backed… Amazon Threat Intelligence has linked widespread compromises of core open-source libraries to a coordinated campaign by North Korea-backed actors using social

North Korean hackers expand open-source software supply chain attacks: Amazon - Bytes Europe

stream:bsky-jetstreamother61d ago kagi ↗

North Korean hackers expand open-source software supply chain attacks: Amazon https://www.byteseu.com/2240016/ North Korean hackers expand open-source software supply chain attacks: Amazon Researchers link DPRK group to attacks on four popular JavaScript libraries underpinning software … Researchers link DPRK group to attacks on four popular JavaScript libraries underpinning software development w

Amazon links four npm attacks to North Korean hackers

kite:cybersecurityother61d ago kagi ↗

Amazon Threat Intelligence said a North Korea-linked group known as Sapphire Sleet was behind four open-source software supply-chain compromises affecting npm packages used in JavaScript development: typo-crypto in March 2025, debug and chalk in September 2025, and axios in March 2026 [bleepingcomputer.com#1][therecord.media#1][thehackernews.com#1][computerweekly.com#1][developer-tech.com#1][there

Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers. https://www. bleepingcomputer.com/news/secu ri

mastodon:infosec-exchangeother61d ago kagi ↗

Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers. https://www. bleepingcomputer.com/news/secu rity/amazon-links-debug-chalk-npm-supply-chain-attacks-to-north-korean-hackers/

Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers https://www. bleepingcomputer.com/news/secu rity/amazon-links-debug-chalk-npm-supply-chain-attacks-to-north-korean-hackers/?u

mastodon:infosec-exchangeother61d ago kagi ↗

Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers https://www. bleepingcomputer.com/news/secu rity/amazon-links-debug-chalk-npm-supply-chain-attacks-to-north-korean-hackers/?utm_source=dlvr.it&utm_medium=%5Binfosec.exchange%5D