Amazon ties North Korean hackers to four open-source compromises

Get the Geopolitics newsletter
Daily geopolitics — wars, elections, sanctions, the diplomatic moves that move markets. Free.
- Amazon Threat Intelligence linked a North Korea-backed hacker group to four open-source compromises dating back to March 2025 — the first time the same financially-motivated actor has been tied to all four: the JavaScript packages typo-crypto, debug, chalk and axios, with axios alone receiving more than 100 million weekly downloads.
- Amazon attributed the campaigns with 'medium confidence'; the group is tracked under multiple names including Sapphire Sleet, Stardust Chollima, BlueNoroff, CageyChameleon and Alluring Pisces.
- Hackers tricked trusted software maintainers into publishing malicious updates, meaning organizations configured to auto-update may have pulled compromised code directly into their systems — making a single compromise potentially far more efficient than targeting organizations individually.
- Amazon Integrated Security CISO CJ Moses told reporters that one successful supply-chain compromise 'can yield access to hundreds, if not more, targeted intrusions,' and framed North Korean hacking as a sanctions-evasion revenue stream that helps finance nuclear and ballistic missile programs.
- Attackers are increasingly splitting malicious payloads across multiple packages that appear harmless individually — one holds encrypted data, another the decryption code, another the execution instructions — so the malicious behavior only emerges when the components are used together.
- Amazon warned that AI is making malicious packages harder to detect by enabling polished code, convincing documentation and fake developer profiles, and that hackers can register non-existent packages that AI coding assistants recommend by mistake.
Why it matters: With axios alone pulled 100 million times a week, even a brief window of compromise gives Pyongyang's hackers potential access to thousands of corporate systems downstream — and Amazon's own CISO explicitly frames the revenue as flowing back to fund North Korea's nuclear and ballistic missile programs, making supply-chain hygiene a direct national-security issue for any organization that auto-updates open-source dependencies.




