threat-intel
North Korean hackers behind major open-source supply chain attacks, Amazon says
High
Summary
North Korean hackers, operating under the alias SapphireSleet, have been responsible for a series of attacks targeting widely used open-source JavaScript packages. These attacks, spanning from March 2025 to March 2026, involved compromising popular libraries like typo-crypto, debug, chalk, and axios, allowing the attackers to steal sensitive data and cryptocurrency. The attacks highlight a growing trend of North Korea leveraging open-source supply chains for cyber theft.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
