LIVE NEWS
  • Ban on neo-Nazi White Australia party is ‘authoritarian’ and breaches constitution, high court hears | Australia news
  • Dell Says AI Will Drive 75 Percent Of Datacenter Demand By 2030
  • London talks raise hopes for green shipping deal
  • Novo Nordisk stops two cardiovascular studies aimed at lowering inflammation
  • Orionx Halts Withdrawals and Winds Down After Alleged $7M Asset Transfers
  • UN Resolution 2758: when interpretation becomes institutional power
  • Reading sci-fi could help us plan for futures stranger than fiction
  • Capital B Raises €25.3M And Buys 376 Bitcoin For Treasury
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»AWS Blames North Korean Group for npm Supply Chain Attacks
Cybersecurity

AWS Blames North Korean Group for npm Supply Chain Attacks

primereportsBy primereportsJuly 31, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
AWS Blames North Korean Group for npm Supply Chain Attacks
Share
Facebook Twitter LinkedIn Pinterest Email


A series of attacks on npm libraries including axios was the work of North Korean actors, AWS has said.

The cloud computing giant said in a blog post on July 29 that compromises of the axios, debug, chalk and typo-crypto libraries were carried out by the same group, known as Saphire Sleet, BlueNoroff and other monikers.

Amazon Threat Intelligence made the connection after analyzing tactics, techniques, and procedures (TTPs) related to the axios attack.

“Amazon Threat Intelligence identified shared TTPs across these supply-chain campaigns, including trojanized NPM packages, use of post-install hooks (scripts that run automatically when a package is installed), and code reuse,” CJ Moses, CISO and VP of security engineering at Amazon, explained.

“Based on analysis of command-and-control (C2) indicators and TTPs, Amazon Threat Intelligence assesses with medium confidence that these campaigns are attributable to the DPRK-linked threat actor tracked as Saphire Sleet.”

Read more on npm attacks: GitHub to Update npm to Thwart Software Supply Chain Attacks

In each of the attacks, the playbook was the same. The group socially engineered the package maintainer then published a software update containing malicious code, meaning any organization that automatically pulled these versions received a compromised update.

Moses said the typo-crypto compromise in March 2025 was likely a test run for the campaigns that followed, which had a much greater reach. Around 10% of cloud environments were affected by the debug and chalk supply chain attacks in a two-hour window, while axios is one of the most popular JavaScript libraries around, with over 100 million weekly downloads.

“By compromising a small number of highly popular packages, the group gains potential access to thousands of downstream environments simultaneously,” said Moses. “For a financially motivated threat actor, this approach is far more efficient than targeting organizations one at a time.”

AWS Details Shifting Attacker Tradecraft

Moses explained that attacker TTPs are evolving when it comes to targeting open source libraries:

  • Attackers are splitting single malicious workflow across several ordinary-looking packages to make detection harder
  • Threat actors often play the long game, behaving like “real maintainers” for weeks or months before publishing their malicious updates
  • Package contents are often benign: it is the external scripts, configuration files and remote endpoints connected to them that are malicious
  • Obfuscation of the malware itself is getting more sophisticated, including “AES‑GCM encrypted blobs gated by passphrases, RC4-style string arrays with per-call keys, layered XOR over base64, and native loaders”
  • Payloads are becoming smarter to evade sandbox analysis
  • Attackers are using slopsquatting techniques – where they register package names that have been hallucinated by AI coding tools in order to increase victim numbers

Despite AWS’s efforts, Cris Thomas, security advocate at Semgrep, argued that attribution is best left to governments and law enforcement.

“Defenders should not concern themselves too much with who is performing an  attack and more with knowing likely techniques of a specific attacker. Distinguishing between one group and another can be helpful for defense teams, knowing whether it is North Korea or Canada is less relevant,” he added.

“As always defenders should rely on defense in depth, if one defense doesn’t find them another one will. The goal isn’t to prevent successful attacks but to identify, limit, block, and correct attacks as soon as possible.”

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleBybit Adds 10 Tokens to Proof-of-Reserves Reporting By Chainwire
Next Article Japan’s Bond-vs-Yen Dilemma Could Shake Bitcoin and Crypto: Analyst
primereports
  • Website

Related Posts

Cybersecurity

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

September 7, 2026
Cybersecurity

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

September 6, 2026
Cybersecurity

Week in review: Claude accounts compromised through infostealer, Patch Tuesday forecast

September 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Threat of further violence looms after Mexican cartel rampage

February 25, 2026116 Views

‘Two-sided risk’ Medicare Advantage plans improve patient outcomes

February 24, 202673 Views

An $18bn settlement – and Zuckerberg barely blinked. The tech titans must be stripped of their power, and soon | Jonathan Freedland

August 28, 202626 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Crypto
  • Cybersecurity
  • Geopolitics
  • Artificial Intelligence
  • Popular Now
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Ban on neo-Nazi White Australia party is ‘authoritarian’ and breaches constitution, high court hears | Australia news
  • Dell Says AI Will Drive 75 Percent Of Datacenter Demand By 2030
  • London talks raise hopes for green shipping deal
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.