Overview
- Amazon Threat Intelligence announced on July 29, 2026 that it has tied compromises of the npm packages typo-crypto, debug, chalk and axios to the same North Korea‑linked group with medium confidence.
- In each case the attackers gained maintainer trust or credentials to publish updates that contained hidden malicious code, a method that lets compromised releases reach downstream systems that pull automatic dependency updates.
- Researchers say the March 2025 typo-crypto incident acted as a rehearsal where a trojan file named core.js waited for a numeric trigger then fetched a second‑stage payload tailored to Windows, macOS or Linux.
- The axios compromise is especially dangerous because the library sees more than 100 million downloads per week, and security firm Wiz found roughly one in ten cloud environments were affected by the debug/chalk incident within about two hours.
- Amazon warns the group splits malicious behavior across packages and uses generative AI to craft believable code and profiles, a trend that heightens long‑term risks for volunteer‑maintained projects and has prompted calls from U.S. officials and registry changes such as npm malware scanning and lifecycle script defaults.