securityonline.info 8/4/2026, 9:31:15 AM · external

North Korean Hackers Hijack NPM Packages via Social Engineering

North Korean Hackers Hijack NPM Packages via Social Engineering
Developing story breach 3 articles tracked
UK Department for Education data breach linked to npm supply chain attack
CyberSIXT Evidence Panel
Primary Source aws.amazon.com
Threat Actor

AMAZON Threat Intelligence has identified a series of supply chain attacks linked to a North Korean hacking group known by several names, including Sapphire Sleet and BlueNoroff. The attacks exploited NPM packages (axios, debug, chalk, and typo-crypto) by socially engineering trusted maintainers to introduce malicious updates. These updates were then automatically downloaded by numerous projects, resulting in extensive reach due to the popularity of the targeted packages.

The group bypassed traditional security measures by manipulating trust rather than exploiting software vulnerabilities. Amazon has advised on protective measures, emphasizing the need for diligent dependency management and awareness of malicious behavior in software supply chains.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline