AWS has attributed a series of npm supply chain attacks targeting popular libraries such as axios to a North Korean group known as Saphire Sleet. The attacks involved social engineering to compromise package maintainers, resulting in malicious updates being pushed to users. AWS's Threat Intelligence unit identified shared tactics across multiple attacks, highlighting the use of trojanized packages and sophisticated evasion techniques.
AWS emphasized the need for organizations to focus on understanding attacker tactics rather than who the attacker is. CJ Moses, Amazon's CISO, noted that the group's method of compromising popular packages allows them to access numerous downstream environments efficiently.