Amazon links four poisoned npm packages to one North Korean crew

← Back to the feed

Amazon links four poisoned npm packages to one North Korean crew

The Register · 3 hours ago

Amazon Web Services says four npm package compromises over the past 18 months were likely carried out by the North Korean-linked Sapphire Sleet group. The alleged campaign relied on social engineering maintainers and abusing trusted publishing accounts, highlighting how attacks on popular open-source dependencies can reach many downstream users at once.

AWS attributes the incidents involving typo-crypto, chalk, debug and Axios with medium confidence, citing shared infrastructure, technical overlaps and similar targeting methods. It says the group moved from obscure packages towards widely used dependencies, while generative AI may help attackers maintain convincing false identities, code and long-running developer-focused scams; Amazon’s wider attribution has not yet been independently confirmed.

  • AWS links four npm compromises to Sapphire Sleet
  • Attackers allegedly targeted maintainers, not npm infrastructure
  • Popular dependencies can expose thousands of downstream environments

Americas Asia Research Science Software Technology World

Read the full article at the source →