Javascript
Image: Mohammad Rahmani / Unsplash

North Korean hackers behind major open-source supply chain attacks, Amazon says

A North Korea-linked hacker group was behind several high-profile compromises of open-source software libraries used by developers worldwide, researchers have found.

In a report released Wednesday, Amazon said the threat actor known as SapphireSleet was responsible for four separate compromises of popular JavaScript packages hosted on the Node Package Manager (NPM) repository.

Amazon said the attackers first compromised the typo-crypto package in March 2025 before targeting the popular debug and chalk packages in September of that year. In March 2026, the same operation appeared to compromise axios, one of the world's most widely used JavaScript libraries, which is downloaded more than 100 million times each week and is embedded in countless web applications and enterprise services.

While security researchers had previously attributed the compromise of the axios library to North Korean hackers, Amazon said the earlier incidents had not previously been publicly linked to the same threat actor.

Earlier in March, Google attributed the axios attack to a North Korean threat actor it tracks as UNC1069. Microsoft linked the same compromise to Sapphire Sleet, which it says overlaps with activity that other vendors track as UNC1069, BlueNoroff, Stardust Chollima, CageyChameleon and Alluring Pisces.

In each attack, Amazon said the hackers gained access by socially engineering a trusted maintainer of the software package before publishing a malicious update. Organizations that automatically installed the latest versions unknowingly downloaded malware.

Researchers have previously said that Sapphire Sleet relies on social engineering rather than software vulnerabilities. The group's attacks are designed to steal passwords, cryptocurrency assets and personal data.

North Korea has increasingly relied on crypto and cyber theft to generate revenue in the face of international sanctions. The country stole more than $2 billion worth of cryptocurrency in 2025, its largest annual haul on record, according to previous reports.

Amazon reported the malware used in the campaign to the Open Source Vulnerabilities database, where it is tracked as MAL-2026-3400.

Open-source software repositories have become increasingly attractive targets for financially motivated hackers, the company said.

Rather than breaking into organizations individually, attackers can compromise a handful of widely used software packages and potentially gain access to thousands of downstream environments at once.

"When an attacker compromises a widely used open source package, every organization that depends on that package is potentially affected," Amazon researchers said.

Get more insights with the
Recorded Future
Intelligence Cloud.
Learn more.
Recorded Future
No previous article
No new articles
Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.