Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers.
The cloud computing giant linked the compromises of the typo-crypto, debug, chalk, and axios libraries to the Sapphire Sleet threat actor, also known as BlueNoroff and Stardust Chollima.
Initial activity started with trojanizing the typo-crypto package in March 2025, which Amazon believes served as a testing ground. It then escalated in September of the same year with the compromise of the widely used debug and chalk packages, affecting an estimated 10% of cloud environments within two hours.
In March 2026, the hacker targeted axios, one of npm's most popular packages with over 100 million weekly downloads.
It should be noted that the axios incident has already been publicly attributed to DPRK-linked actors, but Amazon connected it to the earlier package compromises.









