Home icon

Amazon identifies North Korean hacker group behind open-source supply chain attacks

Security Blog



This article reports Amazon's findings linking a DPRK-linked threat actor to multiple compromises of popular Node Package Manager (NPM) libraries, with analysis of evolving attack techniques and AI's impact on malware development.

  • DPRK-linked group SAPPHIRE SLEET compromised axios, debug, chalk, and typo-crypto NPM packages through social engineering of maintainers
  • Attackers are fragmenting malicious workflows across multiple packages that appear benign individually
  • Threat actors now invest in long-term trust accumulation, maintaining packages for weeks or months before exploitation
  • Malware increasingly uses strong cryptography and environment-aware payloads to evade sandbox detection
  • Generative AI enables attackers to produce convincing code variants and enables "slopsquatting" attacks on AI-hallucinated package names
  • AWS is enhancing Amazon Inspector detection logic and collaborating with industry partners through initiatives like Akrites

AWS emphasizes that open-source software security is a shared responsibility requiring sustained investment and collaboration across the industry.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Aug 4
2026
AWS Security Hub Extended adds supply chain security as its 10th category
Jul 29
2026
Secure your npm and pip package updates in Amazon Linux
Dec 15
2025
Amazon Threat Intelligence identifies Russian cyber threat group targeting Western critical infrastructure
Jul 14
2026
Introducing modularized kernel cryptography in Amazon Linux

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.