North Korean Hackers Exploit npm Packages for Supply Chain Attacks
Key Takeaways North Korean state-sponsored hackers, identified as SAPPHIRE SLEET (aka BlueNoroff), have been exploiting popular npm packages to launch sophisticated supply chain attacks. The...
Key Takeaways
- North Korean state-sponsored hackers, identified as SAPPHIRE SLEET (aka BlueNoroff), have been exploiting popular npm packages to launch sophisticated supply chain attacks.
- The attackers compromised legitimate package maintainer accounts to inject malicious code into widely used packages such as `axios`, `debug`, `chalk`, and `typo-crypto`.
- These campaigns occurred between March 2025 and March 2026, with the `axios` package alone having over 100 million weekly downloads at the time of its compromise.
- The attack leveraged social engineering and stealthy malware with multi-stage payloads, encrypted communications, and persistence mechanisms to evade detection.
- Organizations are urged to enhance their software supply chain security, implement strict dependency management, and monitor for unusual activity in development environments.
North Korean Hackers Exploit npm Packages for Supply Chain Attacks
A sophisticated campaign attributed to North Korean state-sponsored threat actors has been uncovered, revealing their use of compromised npm packages as a vector for widespread software supply chain attacks. These attackers gained unauthorized access to the accounts of legitimate package maintainers, subsequently injecting malicious updates into widely trusted development tools and libraries.
According to an in-depth report by AWS, the group, known by various monikers including SAPPHIRE SLEET, STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, and Alluring Pisces, executed these attacks between March 2025 and March 2026. The affected packages include typo-crypto, debug, <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/a4e12c29-48e9-4acd-a177-2381c39f8832/North-Korean-Hackers-Turn-Trusted-npm-Packages-Into-a-Gateway-for-Supply-Chain-Attacks.pdf?AWSAccessKeyId=ASIA2F3EMEYE2ETXWK2B&Signature=x%2F4sRcdbBO9om9QAXvQU24mJc9I%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEMb%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCULuTwp4uxSAED6w87Y%2Bcy8QL7ZoWKOhKEfE943PsaAgIhAKZQX8WprDC17iuwnFykWVSXLAQRyze%2FalDFRjU%2Buv0ZKvwECI%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgxHBruZOd9temSlKXUq0ATOT5ckvZrkE2ZBohVVkxF3so7g19D4WterWhWi7TcW3zVsgIx9vK%2BF3uragg78CzDWKr%2FaNijIlk9wlK%2FNvCeFSIsPzHJ5peV70LcqzcDkReoHasZihVqTX8jaNXPBpMC8gWBcv%2BPVIiZWFruf7bOzEbxommdZ4%2BZRe9aNF4D5pbTBQ6zOtBhMvGgnEh9AFx5CCNDEZ9IZkncrF5DFRVlqvaSEeltzX59OU%2FxzKdkyI6Ozv8LjjewxvXyXCA5wr239NbkA%2F2yH26nudG0FP7rd0ddJV8PUCT0dNU%2BktdkHS1h%2BI7oUzmgd7QZ1UvHwSekBqpuQ9KOLSVwRcbDNoKILEVlSx9Xt8WJGNwm5SjtQFGqU1MfDiLIZp293jPXhMWpTIAka%2FJ%2Fir9%2FpUlY1S4xgqy7eKBPvLZS0pT3r2mPg9Y%2FgmfvFVyfstpG3t1to8eHnrRPNV%2BFC5jIQAWbfSuKdYUqE6xEzlO4MJJNNa35oKgk9sohOAIB5xsot8GvFklL9uGriZ0gdy3KPNETBaMuuS30mA3l4I95zVQQgHwGo2TxRjPXdWB6Oxz8CUIUz
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.