Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

AWS Blames North Korean Group for npm Supply Chain Attacks

July 31, 2026

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

July 31, 2026

Anthropic Reveals Claude Escaped Testing, Breaching Three Companies

July 31, 2026
Facebook X (Twitter) Instagram
Friday, July 31
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»AWS Blames North Korean Group for npm Supply Chain Attacks
News

AWS Blames North Korean Group for npm Supply Chain Attacks

Team-CWDBy Team-CWDJuly 31, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A series of attacks on npm libraries including axios was the work of North Korean actors, AWS has said.

The cloud computing giant said in a blog post on July 29 that compromises of the axios, debug, chalk and typo-crypto libraries were carried out by the same group, known as Saphire Sleet, BlueNoroff and other monikers.

Amazon Threat Intelligence made the connection after analyzing tactics, techniques, and procedures (TTPs) related to the axios attack.

“Amazon Threat Intelligence identified shared TTPs across these supply-chain campaigns, including trojanized NPM packages, use of post-install hooks (scripts that run automatically when a package is installed), and code reuse,” CJ Moses, CISO and VP of security engineering at Amazon, explained.

“Based on analysis of command-and-control (C2) indicators and TTPs, Amazon Threat Intelligence assesses with medium confidence that these campaigns are attributable to the DPRK-linked threat actor tracked as Saphire Sleet.”

Read more on npm attacks: GitHub to Update npm to Thwart Software Supply Chain Attacks

In each of the attacks, the playbook was the same. The group socially engineered the package maintainer then published a software update containing malicious code, meaning any organization that automatically pulled these versions received a compromised update.

Moses said the typo-crypto compromise in March 2025 was likely a test run for the campaigns that followed, which had a much greater reach. Around 10% of cloud environments were affected by the debug and chalk supply chain attacks in a two-hour window, while axios is one of the most popular JavaScript libraries around, with over 100 million weekly downloads.

“By compromising a small number of highly popular packages, the group gains potential access to thousands of downstream environments simultaneously,” said Moses. “For a financially motivated threat actor, this approach is far more efficient than targeting organizations one at a time.”

AWS Details Shifting Attacker Tradecraft

Moses explained that attacker TTPs are evolving when it comes to targeting open source libraries:

  • Attackers are splitting single malicious workflow across several ordinary-looking packages to make detection harder
  • Threat actors often play the long game, behaving like “real maintainers” for weeks or months before publishing their malicious updates
  • Package contents are often benign: it is the external scripts, configuration files and remote endpoints connected to them that are malicious
  • Obfuscation of the malware itself is getting more sophisticated, including “AES‑GCM encrypted blobs gated by passphrases, RC4-style string arrays with per-call keys, layered XOR over base64, and native loaders”
  • Payloads are becoming smarter to evade sandbox analysis
  • Attackers are using slopsquatting techniques – where they register package names that have been hallucinated by AI coding tools in order to increase victim numbers

Despite AWS’s efforts, Cris Thomas, security advocate at Semgrep, argued that attribution is best left to governments and law enforcement.

“Defenders should not concern themselves too much with who is performing an  attack and more with knowing likely techniques of a specific attacker. Distinguishing between one group and another can be helpful for defense teams, knowing whether it is North Korea or Canada is less relevant,” he added.

“As always defenders should rely on defense in depth, if one defense doesn’t find them another one will. The goal isn’t to prevent successful attacks but to identify, limit, block, and correct attacks as soon as possible.”



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleResearcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Team-CWD
  • Website

Related Posts

News

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

July 31, 2026
News

Anthropic Reveals Claude Escaped Testing, Breaching Three Companies

July 31, 2026
News

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

July 31, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Find your weak spots before attackers do

November 21, 2025

Here’s how to avoid a ‘second strike’

April 11, 2026

Why cybercriminals want to break into your email account

June 29, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.