Home icon

Amazon identifies North Korean hacker group behind open-source supply chain attacks

Security Blog



This article reports Amazon's findings linking a DPRK-linked threat actor to multiple compromises of popular Node Package Manager (NPM) libraries, with analysis of evolving attack techniques and AI's impact on malware development.

  • DPRK-linked group SAPPHIRE SLEET compromised axios, debug, chalk, and typo-crypto NPM packages through social engineering of maintainers
  • Attackers are fragmenting malicious workflows across multiple packages that appear benign individually
  • Threat actors now invest in long-term trust accumulation, maintaining packages for weeks or months before exploitation
  • Malware increasingly uses strong cryptography and environment-aware payloads to evade sandbox detection
  • Generative AI enables attackers to produce convincing code variants and enables "slopsquatting" attacks on AI-hallucinated package names
  • AWS is enhancing Amazon Inspector detection logic and collaborating with industry partners through initiatives like Akrites

AWS emphasizes that open-source software security is a shared responsibility requiring sustained investment and collaboration across the industry.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Dec 15
2025
Amazon Threat Intelligence identifies Russian cyber threat group targeting Western critical infrastructure
Dec 15
2025
What AWS Security learned from responding to recent npm supply chain threat campaigns
Sep 28
2024
Securing Your Software Supply Chain with Amazon CodeCatalyst and Amazon Inspector
Nov 19
2025
New Amazon Threat Intelligence findings: Nation-state actors bridging cyber and kinetic warfare

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.