Wire flash
TechAmazon: North Korean hackers compromised four open-source projects since March
Editorial responsibility
- No named human review is recorded for this page.
- Source reporting is collected, normalized, translated or condensed automatically when needed.
- Automatically published source-backed update
Amazon researchers have linked a North Korean hacker group to four open-source software compromises dating back to March 2025, significantly expanding the known scope of Pyongyang's cyber operations. The financially motivated group, tracked as Sapphire Sleet, Stardust Chollima, BlueNoroff, CageyChameleon, and Alluring Pisces, compromised major JavaScript packages including typo-crypto, debug, chalk, and axios—the latter receiving over 100 million weekly downloads. Amazon's Threat Intelligence attributed the campaigns with medium confidence based on reused code and attack similarities. In each incident, hackers tricked trusted software maintainers to publish malicious updates, potentially compromising thousands of downstream systems. The findings highlight how open-source attacks are becoming harder to detect, with attackers dividing malicious operations across multiple packages that appear harmless individually. North Korea uses such cyber operations for revenue generation to evade sanctions and finance its weapons programs.
Source report
A North Korea-linked hacker group has been tied to four open-source software compromises dating back to March 2025, Amazon researchers announced Wednesday. The findings significantly expand the publicly known scope of Pyongyang's efforts to exploit trusted code to reach large numbers of potential victims and gain access to corporate systems.
Key Findings
The assessment for the first time links the same financially motivated hacking group to compromises of four major JavaScript packages:
- typo-crypto
- debug
- chalk
- axios
These packages serve as building blocks for other software. The axios package alone receives more than 100 million downloads each week, and its compromise had previously been attributed to the North Korean group.
Amazon said Wednesday that it uncovered evidence connecting the actor to the three earlier incidents, based on technical findings that included instances of reused code and similarities in attack methodologies.
Attribution and Tracking
Amazon Threat Intelligence attributed the campaigns to the group with "medium confidence," according to a blog post authored by Amazon Integrated Security CISO CJ Moses, scheduled for release Wednesday evening. The cyber intruders are tracked by researchers under several names, including:
- Sapphire Sleet
- Stardust Chollima
- BlueNoroff
- CageyChameleon
- Alluring Pisces
Attack Methodology
In each incident, the hackers tricked a trusted software maintainer and used that access to publish an update containing malicious code, according to Amazon. Organizations configured to automatically download the latest version of those packages may have pulled the compromised updates directly into their systems.
This approach allows hackers to compromise a small number of widely used packages while potentially gaining access to thousands of downstream systems, making it more efficient than targeting organizations individually.
The Open-Source Ecosystem
Open-source software—code that can be freely inspected, modified, and reused—underpins operating systems, web servers, encryption tools, and many of the applications businesses rely on daily worldwide. These projects often depend on volunteer maintainers to review proposed changes, fix security flaws, and publish updates.
That model relies heavily on trust. Attackers can spend weeks or months posing as legitimate contributors, fixing bugs, and building relationships before attempting to gain control of an established project or publishing a malicious update.
Historical Context
This dynamic drew widespread attention in 2024, when an account operating under the name "Jia Tan" spent years gaining the trust of other developers before attempting to insert a backdoor into XZ Utils, a widely used data-compression tool included in numerous Linux distributions. The backdoor was discovered before it could be broadly deployed.
"Quite frankly, the open-source community is looking for good citizens because these packages are often not maintained by people who are getting paid to do that as a full-time job," said Rick Anthony, senior manager for Amazon's Inspector vulnerability management service, speaking to reporters in Arlington, Va., on Wednesday. "They are very welcoming for anyone who is willing to contribute."
North Korea's Cyber Operations
North Korea has long treated cyber operations as both an intelligence tool and a source of revenue. Its hackers steal cryptocurrency, conduct espionage, and extort victims, while operatives posing as remote IT workers obtain jobs at foreign companies and quietly funnel their salaries back to the regime. Amazon is among those companies, executives said Wednesday. U.S. officials say the proceeds help Pyongyang evade sanctions and finance its nuclear weapons and ballistic missile programs.
"For a sanctions-constrained regime, generating revenue through these operations means that the greater the efficiency, the more money they get, and the more that they can use that money to do things that got them the sanctions to begin with," Moses told reporters. "One successful supply chain compromise can yield access to hundreds, if not more, targeted intrusions."
Evolving Detection Challenges
The findings also illustrate how open-source attacks are becoming harder to detect. Amazon said attackers are increasingly dividing a malicious operation among several packages that appear harmless when reviewed individually. One package may contain encrypted data, another the code needed to unlock it, and a third the instructions to download and execute the final payload. The malicious behavior becomes visible only when the packages are combined.
Source
Defense One - All ContentWestern
Part of this Story
Amazon Uncovers Broad North Korean Hacking Campaign Against Open-Source Software