Amazon Uncovers Broad North Korean Hacking Campaign Against Open-Source Software
Amazon researchers have linked a North Korean hacker group to four open-source software compromises dating back to March 2025, significantly expanding the known scope of Pyongyang's cyber operations. The financially motivated group, tracked as Sapphire Sleet, Stardust Chollima, BlueNoroff, CageyChameleon, and Alluring Pisces, compromised major JavaScript packages including typo-crypto, debug, chalk, and axios—the latter receiving over 100 million weekly downloads. Amazon's Threat Intelligence attributed the campaigns with medium confidence based on reused code and attack similarities. In each incident, hackers tricked trusted software maintainers to publish malicious updates, potentially compromising thousands of downstream systems. The findings highlight how open-source attacks are becoming harder to detect, with attackers dividing malicious operations across multiple packages that appear harmless individually. North Korea uses such cyber operations for revenue generation to evade sanctions and finance its weapons programs.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection