Amazon Threat Intelligence said a North Korea-linked, financially motivated threat actor was tied to four open-source software supply-chain compromises dating back to March 2025. With medium confidence, researchers linked the same actor to malicious updates published for the JavaScript packages typo-crypto, debug, chalk, and axios, after trusted maintainers were reportedly tricked into releasing the tainted versions. The campaign targeted widely used dependencies, including axios, which receives more than 100 million weekly downloads, creating potential exposure across thousands of downstream systems through routine dependency updates.
Amazon said the actor reused code and similar tradecraft across the incidents, indicating a broader coordinated operation rather than isolated package compromises. Researchers warned that attackers are increasingly spreading malicious functionality across multiple packages to make detection harder, while also using AI to produce more convincing code, documentation, and fake developer personas; the report added that coding assistants can further increase risk when they recommend nonexistent package names that attackers later hijack.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Amazon Threat Intelligence linked a March 2026 compromise of the popular npm package axios to the same DPRK-associated supply-chain campaign that previously hit typo-crypto, debug, and chalk. The report said attackers compromised a trusted maintainer and published a malicious update as part of a financially motivated downstream access operation.
Amazon researchers said the same North Korea-linked actor later compromised the npm packages debug and chalk in September 2025 after first targeting typo-crypto in March. Wiz found the debug and chalk incident spread rapidly, affecting about 1 in 10 cloud environments within two hours.
Amazon researchers said a financially motivated North Korea-linked actor was tied to four open-source software supply-chain compromises dating back to March 2025. The campaign involved the JavaScript packages typo-crypto, debug, chalk, and axios, with attackers reportedly tricking trusted maintainers into publishing malicious updates.
Amazon said the open-source supply-chain compromises affecting typo-crypto, debug, chalk, and axios were carried out by the North Korea-linked threat actor SapphireSleet. The report also said the malware used in the campaign is tracked in the Open Source Vulnerabilities database as MAL-2026-3400.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
15 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcescworld.com
Open sourceinfosecurity-magazine.com
Open sourcebleepingcomputer.com
Open sourcemalware.news
Open sourcenextgov.com
Open sourcewiz.io
Open sourceaikido.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.