Amazon Threat Intelligence has linked several high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to the North Korean threat actor Sapphire Sleet. This group is also known as BlueNoroff and Stardust Chollima. The attribution, made with medium confidence, connects incidents that were previously not publicly linked to the same actor.
The initial activity began in March 2025 with the trojanization of the typo-crypto package, which Amazon believes served as a testing ground. This escalated in September 2025 with the compromise of the widely used debug and chalk packages. In March 2026, the same operation appeared to compromise axios, one of npm's most popular packages, downloaded over 100 million times each week.
Amazon states that all three campaigns began with the same method: socially engineering a trusted maintainer. Attackers gained access to accounts by phishing maintainers through lookalike npm domains. Following access, malicious updates were published, which were then automatically distributed to users of the compromised packages. The debug and chalk compromises alone affected an estimated 10% of cloud environments within two hours.
The compromised packages, particularly axios, are embedded in numerous web applications and enterprise services, indicating a broad potential impact. While the axios incident had previously been attributed to North Korean actors by Google (as UNC1069), Amazon's research connects it to earlier package compromises, providing a more comprehensive view of Sapphire Sleet's activities and tradecraft in software supply chain attacks.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Amazon has linked several high-profile npm supply chain attacks, including those targeting the debug, chalk, and axios packages, to the North Korean threat actor Sapphire Sleet (BlueNoroff/Stardust Chollima). The attackers gained access by socially engineering package maintainers and published malicious updates, affecting a significant portion of cloud environments. This attribution highlights evolving tactics in software supply chain attacks, including multi-stage payloads and environment-aware malware.
Amazon's security researchers have identified the North Korea-linked group SapphireSleet as responsible for four compromises of popular JavaScript packages on NPM, including axios. These attacks involved socially engineering maintainers to publish malicious updates, impacting organizations that automatically installed the compromised versions.
Amazon Threat Intelligence has attributed the September 2025 hijack of the npm packages debug and chalk, along with other compromises, to North Korea's Sapphire Sleet group. This attribution connects previously separate incidents of crypto theft and package compromise under a single threat actor, highlighting a consistent pattern of social engineering and supply chain attacks.