AMAZON Threat Intelligence has identified a series of supply chain attacks linked to a North Korean hacking group known by several names, including Sapphire Sleet and BlueNoroff. The attacks exploited NPM packages (axios, debug, chalk, and typo-crypto) by socially engineering trusted maintainers to introduce malicious updates. These updates were then automatically downloaded by numerous projects, resulting in extensive reach due to the popularity of the targeted packages.
The group bypassed traditional security measures by manipulating trust rather than exploiting software vulnerabilities. Amazon has advised on protective measures, emphasizing the need for diligent dependency management and awareness of malicious behavior in software supply chains.