← Back to Tech & Science

Amazon Links Major npm Supply Chain Attacks to North Korean Hackers

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

SEATTLE — Amazon Web Services has identified a series of high-profile supply chain attacks targeting the global open-source software ecosystem as the work of state-sponsored actors from North Korea. The cloud computing giant announced on Wednesday that threat groups known as Sapphire Sleet, BlueNoroff, and Stardust Chollima were responsible for compromising popular libraries hosted on npm, one of the world's largest registries for JavaScript packages.

The attacks represent a significant escalation in cyber operations against software infrastructure used by developers worldwide. By injecting malicious code into widely trusted open-source projects, the North Korean actors gained indirect access to downstream victims who integrated these compromised components into their own applications and systems. Amazon stated that the primary motivation behind the campaign appears to be financial gain, alongside the strategic objective of establishing persistent footholds within critical digital infrastructures.

The Sapphire Sleet group has previously been linked to cryptocurrency theft operations, while BlueNoroff is known for targeting government entities in South Korea. The involvement of Stardust Chollima adds a new dimension to the campaign, as this actor has historically focused on espionage and data exfiltration. In these recent incidents, all three groups coordinated efforts to infiltrate npm packages with high download counts, ensuring maximum reach among unsuspecting developers.

Amazon's security team detected anomalies in package metadata and code signatures that triggered an immediate investigation. Upon isolating the malicious artifacts, engineers traced the digital footprints back to infrastructure associated with North Korean state-sponsored cyber units. The company has since removed the compromised packages from its repositories and issued alerts to affected users globally. Developers are urged to audit their dependencies immediately and update systems to versions verified as clean.

The incident highlights the growing vulnerability of modern software supply chains, where a single compromise can ripple through thousands of dependent applications. Unlike direct attacks on corporate networks, these operations rely on trust in open-source maintainers, making detection more difficult until malicious code is executed downstream. Security experts note that the sophistication of the injection methods suggests state-level resources and long-term planning.

While Amazon has contained the immediate threat within its ecosystem, questions remain regarding the full extent of the damage caused by the compromised packages before their removal. It is unclear how many organizations have already integrated the malicious code into production environments or if data exfiltration occurred prior to detection. Furthermore, investigators are working to determine whether these groups will attempt similar attacks on other package registries beyond npm.

The North Korean government has not commented on the allegations. As developers scramble to patch vulnerabilities and reset trust in affected libraries, the incident serves as a stark reminder of the risks inherent in relying on shared codebases for critical infrastructure.

Discussion

0 / 2000