// DOSSIER — amazon-links-north-korean-hacking-group-open-source
Amazon Links North Korean Hacking Group to Coordinated Open-Source Supply Chain Campaign
REL_TIME: 31 Jul 2026 22:27Z · LANG: EN
Amazon Threat Intelligence has identified a coordinated campaign by a North Korean state-sponsored hacking group targeting the global open-source software supply chain. By linking four major JavaScript package compromises—typo-crypto, debug, chalk, and axios—researchers revealed an industrial operation active since early 2025. The attackers utilized social engineering to gain the trust of package maintainers, allowing them to inject malicious code into libraries that receive hundreds of millions of weekly downloads. This campaign aims to gain broad access to downstream enterprise systems to generate revenue for the North Korean regime, bypassing international sanctions and funding military programs.
// Background
Open-source software relies on a trust-based model where volunteer maintainers often lack the resources to vet every contribution. North Korea has a long history of using cyber operations, including cryptocurrency theft and IT worker infiltration, to sustain its economy under global sanctions. The 2024 XZ Utils backdoor incident previously highlighted the extreme risk of long-term social engineering in open-source projects.
// Key Developments
- Attributed the campaign to the North Korean group tracked as Sapphire Sleet, BlueNoroff, or APT38.
- Identified compromises in four widely used NPM packages: typo-crypto, debug, chalk, and axios.
- Axios alone has over 100 million weekly downloads, while debug and chalk exceed 1 billion combined.
- Attackers used social engineering to pose as legitimate contributors and gain maintainer access to publish malicious updates.
- Warned of 'slopsquatting,' where attackers exploit AI coding assistant errors to register and distribute malicious packages.
- Amazon launched the Akrites initiative with a $12.5 million investment to secure open-source software against AI-enabled threats.
// Timeline
-
Initial compromise of the typo-crypto package, assessed by Amazon as a rehearsal to test the group's playbook.
-
Coordinated compromises of the popular debug and chalk libraries, affecting approximately 10% of cloud environments.
-
Breach of an axios package maintainer via social engineering to inject malicious code into the widely used HTTP client.
-
Amazon publicly releases findings linking all four incidents to the same North Korean state-sponsored actor.
// Perspectives
[Amazon Threat Intelligence]
Views the campaign as a sophisticated, nation-state industrial operation and is advocating for shared industry responsibility and investment in security tools.
[U.S. Government Officials]
Concerned that these cyber operations provide a critical revenue stream for North Korea to fund nuclear and ballistic missile programs while evading international sanctions.
[Cybersecurity Researchers (Wiz/Socket)]
Emphasize the rapid scale of impact, noting that 1 in 10 cloud environments were affected within two hours of the debug and chalk compromises.
// Quotes
“One successful supply chain compromise can yield access to hundreds, if not more, targeted intrusions.”
“They’re not breaking the open-source systems, they’re using it as designed, just for a different purpose.”
“The open-source community is looking for good citizens because these packages are often not maintained by people who are getting paid to do that as a full-time job.”