Amazon Ties Multiple NPM Package Compromises to North Korean Threat Actor SAPPHIRE SLEET
Key Takeaways
- ▸A single DPRK-linked threat actor is behind compromises of multiple critical NPM packages (axios, debug, chalk, typo-crypto), marking the first public attribution of these incidents to SAPPHIRE SLEET and its known aliases
- ▸The threat actor uses consistent tactics: social engineering of package maintainers, trojanized packages with post-install hooks, and code reuse across campaigns to maximize reach
- ▸Axios compromise in March 2026 is particularly significant, as the library has 100+ million weekly downloads, potentially exposing millions of downstream organizations to malicious code
Summary
Amazon Threat Intelligence has identified a DPRK-linked threat actor known by multiple names including SAPPHIRE SLEET, STARDUST CHOLLIMA, and BlueNoroff as responsible for a coordinated series of compromises against popular Node Package Manager (NPM) libraries. The research reveals that compromises of widely-used packages including axios (with over 100 million weekly downloads), debug, chalk, and typo-crypto were carried out by the same threat actor using consistent tactics: social engineering of trusted maintainers, trojanized packages, and post-install hooks to deliver malicious code. This represents the first time Amazon Threat Intelligence has publicly connected these separate incidents to a single DPRK-linked group.
The findings underscore an escalating pattern of financially motivated software supply chain attacks since the 2024 XZ Utils backdoor incident. Amazon's research also highlights an emerging threat: generative AI is beginning to change the nature of malicious software packages, with threat actors already probing AI-based code systems. The successful compromise of axios—one of the JavaScript ecosystem's most critical dependencies—demonstrates the severe potential impact when widely-trusted open-source libraries are weaponized against downstream organizations worldwide.
- Generative AI is already being leveraged in malware development, with threat actors probing AI-based code systems and adapting their techniques accordingly
- Software supply chain attacks have increased significantly in volume and sophistication since 2024, driven primarily by DPRK-linked threat actors and other cybercriminal groups
Editorial Opinion
This research exposes a fundamental vulnerability in how the global software supply chain operates: a small number of volunteer-maintained open-source packages have become single points of failure for millions of organizations. The concentration of trust in libraries like axios means that compromising one package can cascade risk across the entire digital economy. As generative AI tools accelerate malware development and threat actors grow more sophisticated in targeting maintainers, the ecosystem urgently needs structural changes—from better funding for critical projects to more rigorous verification mechanisms—to prevent state-sponsored actors from weaponizing the building blocks of modern software.



