Amazon linked a series of npm supply-chain compromises involving typo-crypto, debug, chalk, and axios to the North Korean Sapphire Sleet threat actor, also known as BlueNoroff and Stardust Chollima. The campaign used social engineering, malicious package updates, and evolving stealth techniques, while Amazon also backed community defenses and the Akrites initiative. #SapphireSleet #BlueNoroff #StardustChollima #npm #axios #debug #chalk #typo-crypto #OpenSSF #Akrites
Keypoints
- Amazon tied multiple npm package compromises to Sapphire Sleet.
- The attacks targeted typo-crypto, debug, chalk, and axios.
- Attackers socially engineered maintainers to push malicious updates.
- The campaign showed stronger encryption, multi-stage payloads, and environment-aware behavior.
- Amazon is sharing intelligence and supporting the Akrites initiative.