< Back to all clusters
[TECHNOLOGY] · North Korea, United States · 4 sources

North Korean hackers compromise npm packages axios, debug, and chalk

Amazon Threat Intelligence has uncovered a coordinated North Korean supply‑chain campaign that targets the open‑source JavaScript ecosystem. The attackers compromised high‑traffic npm packages—including axios, debug and chalk—by using sophisticated social‑engineering, AI‑generated developer identities, and a novel “distributed payload” technique that splits malicious code across multiple seemingly benign packages to evade detection. The operation aims to steal cryptocurrency to fund the DPRK’s nuclear and missile programs and to conduct strategic espionage across downstream corporate systems.

Amazon researchers also linked the recent axios breach to an earlier rehearsal in March 2025 involving a little‑noticed package called typo‑crypto, followed by compromises of debug and chalk in September 2025. The group, tracked under names such as UNC1069, Sapphire Sleet and Stardust Chollima, used AI‑enhanced code and custom activation triggers to avoid analysis, demonstrating a growing capability to infiltrate globally used software components.

Entities: Amazon Threat Intelligence · North Korean state‑sponsored hacking groups · axios (npm package) · chalk (npm package) · debug (npm package)