Particle.news
Download on the App Store

Amazon Links North Korea‑Tied Hackers to Four npm Package Compromises

Amazon says the activity shows a North Korea‑linked actor exploits trusted maintainers using AI to seed malware into widely used code, raising supply‑chain risk for cloud and production systems.

Overview

  • Amazon Threat Intelligence announced on July 29, 2026 that it has tied compromises of the npm packages typo-crypto, debug, chalk and axios to the same North Korea‑linked group with medium confidence.
  • In each case the attackers gained maintainer trust or credentials to publish updates that contained hidden malicious code, a method that lets compromised releases reach downstream systems that pull automatic dependency updates.
  • Researchers say the March 2025 typo-crypto incident acted as a rehearsal where a trojan file named core.js waited for a numeric trigger then fetched a second‑stage payload tailored to Windows, macOS or Linux.
  • The axios compromise is especially dangerous because the library sees more than 100 million downloads per week, and security firm Wiz found roughly one in ten cloud environments were affected by the debug/chalk incident within about two hours.
  • Amazon warns the group splits malicious behavior across packages and uses generative AI to craft believable code and profiles, a trend that heightens long‑term risks for volunteer‑maintained projects and has prompted calls from U.S. officials and registry changes such as npm malware scanning and lifecycle script defaults.