Amazon identifies North Korean hacker group behind open-source supply chain attacks
Security Blog
This article reports Amazon's findings linking a DPRK-linked threat actor to multiple compromises of popular Node Package Manager (NPM) libraries, with analysis of evolving attack techniques and AI's impact on malware development.
- DPRK-linked group SAPPHIRE SLEET compromised axios, debug, chalk, and typo-crypto NPM packages through social engineering of maintainers
- Attackers are fragmenting malicious workflows across multiple packages that appear benign individually
- Threat actors now invest in long-term trust accumulation, maintaining packages for weeks or months before exploitation
- Malware increasingly uses strong cryptography and environment-aware payloads to evade sandbox detection
- Generative AI enables attackers to produce convincing code variants and enables "slopsquatting" attacks on AI-hallucinated package names
- AWS is enhancing Amazon Inspector detection logic and collaborating with industry partners through initiatives like Akrites
AWS emphasizes that open-source software security is a shared responsibility requiring sustained investment and collaboration across the industry.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
2025
2025
2024
2025
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.