Amazon identifies North Korean hackers as behind supply chain attack that compromised four npm packages

TL;DR AI
2 min readKey summary
Amazon Threat Intelligence said the North Korean group SAPPHIRE SLEET was behind a series of npm supply-chain attacks.
Between March 2025 and March 2026, widely used packages including typo-crypto, debug, chalk, and axios were compromised.
Attackers used trojanized npm updates and social engineering to win developer trust and spread malicious code.
The case shows how abuse of trusted open-source dependencies can cascade into many cloud and application environments.
