Amazon links North Korea to four open-source compromises

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Amazon Threat Intelligence linked a North Korea-backed hacker group to four open-source JavaScript package compromises dating to March 2025—typo-crypto, debug, chalk, and axios—revealing a larger operation than previously known.
- The axios package alone receives more than 100 million weekly downloads, and organizations configured to auto-update may have pulled the malicious updates directly into their systems, giving attackers potential access to thousands of downstream environments.
- Amazon attributed the campaigns to the same group with "medium confidence"; the actor is tracked under multiple names including Sapphire Sleet, Stardust Chollima, BlueNoroff, CageyChameleon, and Alluring Pisces.
- Attackers tricked trusted software maintainers by posing as legitimate contributors—spending weeks or months fixing bugs and building relationships before publishing malicious updates, a tactic that drew attention in the 2024 "Jia Tan" XZ Utils backdoor attempt.
- Amazon warned attackers are splitting malicious operations across multiple packages that appear harmless individually, with the malicious behavior only visible when the components are used together, and are using AI to produce polished code, convincing documentation, and fake developer profiles.
- Hackers can also exploit errors made by AI coding assistants: if a tool recommends a package that doesn't exist, attackers can register the name and load it with malware, hoping developers download it without realizing the recommendation was a hallucination.
- CJ Moses, Amazon's Integrated Security CISO, said the proceeds help Pyongyang evade sanctions and finance its nuclear weapons and ballistic missile programs—making one successful supply-chain compromise equivalent to "hundreds, if not more, targeted intrusions."
Why it matters: A single compromise of a package downloaded 100 million times weekly can deliver access to hundreds or thousands of organizations at once, making supply-chain attacks disproportionately efficient for revenue-starved Pyongyang. With attackers now splitting payloads across multiple benign-looking packages and using AI to erase sloppy tells, traditional single-package code review can no longer catch the campaign—putting the volunteer-maintained code underpinning military and civilian systems at structural risk.




