Amazon identifies North Korean hacker group behind open-source supply chain attacks

2026-07-29 Amazon

https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks

Thumbnail for Amazon identifies North Korean hacker group behind open-source supply chain attacks

Amazon Threat Intelligence attributes the typo-crypto, debug, chalk, and axios NPM compromises with medium confidence to a DPRK-linked actor tracked under names including SAPPHIRE SLEET, STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, and Alluring Pisces. The actor socially engineered trusted maintainers and published trojanized updates, allowing a small number of package compromises to reach many downstream environments. The earlier typo-crypto implant contacted npmjs.store, supported Windows, macOS, and Linux payloads, and appears to have tested techniques later used against more popular libraries. Amazon also warns that attackers are distributing malicious behavior across packages, gating execution to evade sandboxes, and using generative AI and indirect prompt injection to defeat automated review.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 2014d09c7ded74d89c885b5f1169386… 2026-07-29 2026-07-29
HASH 24604384b0e748ada07923630b3d037… 2026-07-29 2026-07-29
IPv4 216.74.123.126 2026-07-29 2026-07-29
DOMAIN npmjs.store 2026-07-29 2026-07-29

Related Actors

Related Reports

« Back