Close Menu
NCIJ Network NCIJ Network
    What's Hot

    For the First Time, Zoox Can Charge People for Rides in Its Steering-Wheel-Free Robotaxis

    July 30, 2026

    VMware fixes three critical flaws allowing auth bypass, VM escapes

    July 30, 2026

    JPMorgan, Citi, UBS test tokenized cross-border payments in BIS pilot

    July 30, 2026
    Facebook X (Twitter) Instagram
    Trending
    • For the First Time, Zoox Can Charge People for Rides in Its Steering-Wheel-Free Robotaxis
    • VMware fixes three critical flaws allowing auth bypass, VM escapes
    • JPMorgan, Citi, UBS test tokenized cross-border payments in BIS pilot
    • Costa Rica banana plantation destroyed protected wetland, complaint alleges
    • We Energies says Oracle dispute won’t derail Port Washington data center
    • Lindsey Graham’s Russia Sanctions Bill Is Getting Closer to Passage
    • UN demands end of Ugandan clampdown on dissent | United Nations News
    • The Guardian view on ‘kidulthood’: Britain prices young adults out of independent life | Editorial
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, July 30
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 30, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers.

    The cloud computing giant linked the compromises of the typo-crypto, debug, chalk, and axios libraries to the Sapphire Sleet threat actor, also known as BlueNoroff and Stardust Chollima.

    Initial activity started with trojanizing the typo-crypto package in March 2025, which Amazon believes served as a testing ground. It then escalated in September of the same year with the compromise of the widely used debug and chalk packages, affecting an estimated 10% of cloud environments within two hours.

    image

    In March 2026, the hacker targeted axios, one of npm’s most popular packages with over 100 million weekly downloads.

    It should be noted that the axios incident has already been publicly attributed to DPRK-linked actors, but Amazon connected it to the earlier package compromises.

    Amazon says the attacker gained access by socially engineering package maintainers, and then published malicious updates that were automatically distributed to unsuspecting users.

    The attribution to Sapphire Sleet has medium confidence and is based on the shared tactics, techniques, and procedures (TTPs) observed in the campaign, the command-and-control (C2) infrastructure, and various operational similarities.

    Also, the researchers believe the attacker had a financial motivation, targeting popular packages to gain indirect access to a large pool of potential downstream victims at once.

    Amazon also highlights several trends that have emerged from the recent supply-chain attacks:

    • Attackers are splitting malicious functionality across multiple seemingly benign packages, making detection more difficult.
    • Threat actors are spending months building trust by maintaining legitimate projects or becoming contributors before introducing malicious code.
    • Malicious behavior is increasingly decoupled from package contents, relying on external scripts, configuration files, or servers that can be weaponized later.
    • Malware is using stronger encryption and multi-stage payloads, with runtime or remotely fetched keys that hinder static analysis.
    • Payloads are becoming environment-aware, delaying execution unless they detect real developer or production environments to evade analysis sandboxes.
    • Attackers are increasingly exploiting “slopsquatting” by registering package names hallucinated by AI coding assistants, hoping developers or autonomous coding agents will install them.

    Many of these tactics are enhanced and simplified by AI, Amazon explains, as they help attackers generate code, documentation, and maintainer identities.

    Amazon highlighted a multi-faceted response to these dangers, including reporting its findings and intelligence to the community, collaborating with OpenSSF and other industry partners, and investing $12.5M in the Akrites initiative, which helps protect critical open-source software from AI-enabled attacks.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    Amazon attacks Chalk Debug hackers Korean links North npm supplychain
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    VMware fixes three critical flaws allowing auth bypass, VM escapes

    Timeless Compliance: Why Better Questions Beat Bigger Frameworks

    ShinyHunters claims Brinks Home breach, threatens to leak stolen data

    Analog Devices discloses data breach, says operations unaffected

    After the Break-In: What Attackers Do Once They’re Already Inside

    Hundreds of migrants enter Spain’s north African territory Ceuta from Morocco

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    For the First Time, Zoox Can Charge People for Rides in Its Steering-Wheel-Free Robotaxis

    July 30, 2026

    VMware fixes three critical flaws allowing auth bypass, VM escapes

    July 30, 2026

    JPMorgan, Citi, UBS test tokenized cross-border payments in BIS pilot

    July 30, 2026

    Costa Rica banana plantation destroyed protected wetland, complaint alleges

    July 30, 2026
    Latest Posts

    Advancing the next era of national science

    July 22, 2026

    Arcee, a US open source AI lab, says Chinese models are not inherently dangerous

    July 22, 2026

    Most bus fares in England to be capped at £2 from January

    July 22, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    For the First Time, Zoox Can Charge People for Rides in Its Steering-Wheel-Free Robotaxis

    July 30, 2026

    VMware fixes three critical flaws allowing auth bypass, VM escapes

    July 30, 2026

    JPMorgan, Citi, UBS test tokenized cross-border payments in BIS pilot

    July 30, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.