Amazon identifies North Korean hacker group behind open-source supply chain attacks
2026-07-29 • Amazon •
Amazon Threat Intelligence attributes the typo-crypto, debug, chalk, and axios NPM compromises with medium confidence to a DPRK-linked actor tracked under names including SAPPHIRE SLEET, STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, and Alluring Pisces. The actor socially engineered trusted maintainers and published trojanized updates, allowing a small number of package compromises to reach many downstream environments. The earlier typo-crypto implant contacted npmjs.store, supported Windows, macOS, and Linux payloads, and appears to have tested techniques later used against more popular libraries. Amazon also warns that attackers are distributing malicious behavior across packages, gating execution to evade sandboxes, and using generative AI and indirect prompt injection to defeat automated review.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 2014d09c7ded74d89c885b5f1169386… | 2026-07-29 | 2026-07-29 |
| HASH | 24604384b0e748ada07923630b3d037… | 2026-07-29 | 2026-07-29 |
| IPv4 | 216.74.123.126 | 2026-07-29 | 2026-07-29 |
| DOMAIN | npmjs.store | 2026-07-29 | 2026-07-29 |