Particle.news
Download on the App Store

Amazon Links Four npm Supply‑Chain Hacks to North Korea‑Linked Actor

The company says the campaign used maintainer social engineering and evolving multi‑stage tradecraft that can push malicious updates broadly, prompting registry changes and new industry funding.

Overview

  • Amazon disclosed Wednesday that its Threat Intelligence team has tied compromises of axios, debug, chalk and typo‑crypto to a single DPRK‑linked threat actor and assesses the attribution with medium confidence.
  • Researchers say the attackers gained access by socially engineering trusted package maintainers and publishing malicious updates that would install automatically for downstream users.
  • Amazon traces the campaign back to a March 2025 trojanized package it considers a rehearsal, followed by debug and chalk in September 2025 and the high‑profile axios compromise in March 2026.
  • The scale of the risk is large because axios is downloaded more than 100 million times per week and security firm Wiz found the debug/chalk incident affected about one in ten cloud environments within two hours.
  • Registries and vendors are rolling out defenses — npm flipped lifecycle‑script defaults and began pre‑publish malware scans in late July — while Amazon is funding collaborative projects including Akrites and sharing indicators as verification and remediation continue.