'Generative AI is already changing what malicious software packages look like and how threat actors are beginning…
- Amazon links multiple software supply chain attacks to one North Korean hacking group
- Generative AI enables convincing malware hidden inside trusted software packages at scale
- Attackers manipulated trusted maintainers before distributing compromised software updates to developers
Amazon has linked a North Korean threat actor to several recent compromises of popular NPM software libraries.
A report from Amazon Threat Intelligence connected recent breaches of the axios, debug, chalk, and typo-crypto packages to a single group.
That group is tracked across the security community under names including SAPPHIRE SLEET, STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, and Alluring Pisces.
Attackers exploit trust to compromise widely used packages
In March 2025, the threat actor compromised the typo-crypto package through a trojanized file disguised as a legitimate dependency.
The same group later compromised debug and chalk in September 2025, then axios in March 2026.
Axios alone carries more than 100 million weekly downloads, making it one of...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE