Security
Amazon Threat Intelligence has linked four high-profile compromises of widely used Node Package Manager (NPM) libraries to the same North Korean state-sponsored threat actor, marking the first public attribution connecting the software supply-chain attacks.
The company said the compromises of the axios, debug, chalk and typo-crypto packages were carried out by the DPRK-linked group tracked by the security community as SAPPHIRE SLEET, also known as STARDUST CHOLLIMA, BlueNoroff, CageyChameleon and Alluring Pisces.
According to Amazon, the threat actor gained access by socially engineering trusted maintainers of popular open-source projects before publishing malicious software updates. Organisations that automatically installed the latest versions of the compromised packages unknowingly downloaded malware into their development environments.
Amazon said that while the compromise of the widely used axios package had previously been attributed to the North Korean group, this is the first time the earlier attacks targeting typo-crypto, debug and chalk have been publicly linked to the same actor. The assessment is based on shared command-and-control infrastructure, code reuse and common tactics, techniques and procedures observed across the campaigns.
The findings suggest the attacks formed part of a coordinated campaign aimed at compromising a small number of highly trusted open-source components to gain access to thousands of downstream software environments simultaneously. Amazon described the approach as significantly more efficient than targeting individual organisations one at a time.
Amazon's investigation also found that the campaign appears to have begun earlier than previously understood. Researchers traced activity back to a compromise of the typo-crypto package in March 2025, which they believe served as a testing ground before the larger attacks against debug, chalk and axios.
Beyond the attribution, the report warns that software supply-chain attacks are becoming increasingly sophisticated. Rather than embedding all malicious functionality inside a single package, attackers are now distributing payloads across multiple seemingly benign packages, relying on runtime behaviour and external infrastructure to evade traditional code-scanning tools.
Amazon also said generative AI is changing the software supply-chain threat landscape by enabling attackers to produce convincing source code, documentation and developer identities at scale. The company warned that threat actors are beginning to exploit AI coding assistants through techniques such as "slopsquatting," in which malicious packages are registered under names hallucinated by AI tools, and predicted that prompt injection techniques will increasingly target AI-powered code review systems.
The findings underscore growing concerns about the security of the open-source software ecosystem, which underpins much of the world's cloud infrastructure, enterprise applications and software development pipelines. As organisations accelerate software development with AI-assisted coding tools, security researchers expect software supply-chain attacks to become increasingly targeted, automated and difficult to detect.
The company said the compromises of the axios, debug, chalk and typo-crypto packages were carried out by the DPRK-linked group tracked by the security community as SAPPHIRE SLEET, also known as STARDUST CHOLLIMA, BlueNoroff, CageyChameleon and Alluring Pisces.
According to Amazon, the threat actor gained access by socially engineering trusted maintainers of popular open-source projects before publishing malicious software updates. Organisations that automatically installed the latest versions of the compromised packages unknowingly downloaded malware into their development environments.
Amazon said that while the compromise of the widely used axios package had previously been attributed to the North Korean group, this is the first time the earlier attacks targeting typo-crypto, debug and chalk have been publicly linked to the same actor. The assessment is based on shared command-and-control infrastructure, code reuse and common tactics, techniques and procedures observed across the campaigns.
The findings suggest the attacks formed part of a coordinated campaign aimed at compromising a small number of highly trusted open-source components to gain access to thousands of downstream software environments simultaneously. Amazon described the approach as significantly more efficient than targeting individual organisations one at a time.
Amazon's investigation also found that the campaign appears to have begun earlier than previously understood. Researchers traced activity back to a compromise of the typo-crypto package in March 2025, which they believe served as a testing ground before the larger attacks against debug, chalk and axios.
Beyond the attribution, the report warns that software supply-chain attacks are becoming increasingly sophisticated. Rather than embedding all malicious functionality inside a single package, attackers are now distributing payloads across multiple seemingly benign packages, relying on runtime behaviour and external infrastructure to evade traditional code-scanning tools.
Amazon also said generative AI is changing the software supply-chain threat landscape by enabling attackers to produce convincing source code, documentation and developer identities at scale. The company warned that threat actors are beginning to exploit AI coding assistants through techniques such as "slopsquatting," in which malicious packages are registered under names hallucinated by AI tools, and predicted that prompt injection techniques will increasingly target AI-powered code review systems.
The findings underscore growing concerns about the security of the open-source software ecosystem, which underpins much of the world's cloud infrastructure, enterprise applications and software development pipelines. As organisations accelerate software development with AI-assisted coding tools, security researchers expect software supply-chain attacks to become increasingly targeted, automated and difficult to detect.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




