North Korean hackers behind major open-source supply chain attacks, Amazon says

A North Korea-linked hacker group was behind several high-profile compromises of open-source software libraries used by developers worldwide, researchers have found.
In a report released Wednesday, Amazon said the threat actor known as SapphireSleet was responsible for four separate compromises of popular JavaScript packages hosted on the Node Package Manager (NPM) repository.
Amazon said the attackers first compromised the typo-crypto package in March 2025 before targeting the popular debug and chalk packages in September of that year. In March 2026, the same operation appeared to compromise axios, one of the world's most widely used JavaScript libraries, which is downloaded more than 100 million times each week and is embedded in countless web applications and enterprise services.
While security researchers had previously attributed the compromise of the axios library to North Korean hackers, Amazon said the earlier incidents had not previously been publicly linked to the same threat actor.
Earlier in March, Google attributed the axios attack to a North Korean threat actor it tracks as UNC1069. Microsoft linked the same compromise to Sapphire Sleet, which it says overlaps with activity that other vendors track as UNC1069, BlueNoroff, Stardust Chollima, CageyChameleon and Alluring Pisces.
In each attack, Amazon said the hackers gained access by socially engineering a trusted maintainer of the software package before publishing a malicious update. Organizations that automatically installed the latest versions unknowingly downloaded malware.
Researchers have previously said that Sapphire Sleet relies on social engineering rather than software vulnerabilities. The group's attacks are designed to steal passwords, cryptocurrency assets and personal data.
North Korea has increasingly relied on crypto and cyber theft to generate revenue in the face of international sanctions. The country stole more than $2 billion worth of cryptocurrency in 2025, its largest annual haul on record, according to previous reports.
Amazon reported the malware used in the campaign to the Open Source Vulnerabilities database, where it is tracked as MAL-2026-3400.
Open-source software repositories have become increasingly attractive targets for financially motivated hackers, the company said.
Rather than breaking into organizations individually, attackers can compromise a handful of widely used software packages and potentially gain access to thousands of downstream environments at once.
"When an attacker compromises a widely used open source package, every organization that depends on that package is potentially affected," Amazon researchers said.
References in this story
- Amazon identifies North Korean hacker group behind open-source supply chain attacks | Amazon Web Services aws.amazon.com Amazon is sharing new findings about how a threat actor linked to the Democratic People’s Republic of Korea (DPRK) is targeting open source software libraries, the shared building blocks that companies around the world…
- Google links axios supply chain attack to North Korean group therecord.media Google Threat Intelligence Group (GTIG) joined several other researchers in attributing the attack to a North Korean threat actor they call UNC1069. SentinelOne found the same group using macOS-based malware in attacks…
- Mitigating the Axios npm supply chain compromise | Microsoft Security Blog www.microsoft.com On March 31, 2026, the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages for version updates to download from command and control (C2) that Microsoft Threat…
- Dissecting Sapphire Sleet’s macOS intrusion from lure to compromise | Microsoft Security Blog www.microsoft.com The Microsoft Defender Security Research Team uncovered a sophisticated macOS intrusion campaign attributed to the North Korean threat actor Sapphire Sleet that abuses user driven execution and social engineering to…
- ‘It reads like a spy novel’: $280 million theft from Drift involved North Korean fake companies, cutouts therecord.media Drift officials said the operation began six months ago, when they were approached at a cryptocurrency conference by members of a company claiming to focus on quantitative trading.
- Over $3.4 billion in crypto stolen throughout 2025, with North Korea again the top culprit therecord.media Of the $3.4 billion in crypto stolen from January to December, Chainalysis attributed at least $2.02 billion to North Korean hackers.
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your business.
- Daryna Antoniuk (@darynant.bsky.social) bsky.app Cybersecurity Reporter at Recorded Future News. Ex at The Kyiv Independent/Forbes/The Kyiv Post 📍Kyiv, Ukraine



