Amazon Threat Intelligence assessed with medium confidence that supply chain attacks on the axios, debug, chalk and typo-crypto NPM packages over the past two years were conducted by the North Korean threat actor known as Sapphire Sleet, according to an AWS security blog published Wednesday.Sapphire Sleet, also known as BlueNoroff, Stardust Chollima, CageyChameleon and Alluring Pisces, is a threat group sponsored by the Democratic People’s Republic of Korea (DPRK) that is known to spread cryptocurrency-stealing malware for financial gain. The group has also been involved in North Korea’s remote IT worker schemes to bring funding back to the regime.The axios, debug and chalk, and typo-crypto NPM packages were compromised in three separate campaigns that have now been linked together by Amazon researchers due to overlapping tactics, techniques and procedures (TTPs), command-and-control (C2) artifacts, and reused code, according to the blog post authored by Amazon Integrated Security CISO CJ Moses.The typo-crypto package, a lesser-known package compromised with a malicious commit in March 2025, was identified by Amazon Threat Intelligence during its investigation into the TTPs and indicators involved in the attack on the axios package, which was compromised in March 2026 and had about 100 million weekly downloads at the time of the attack.Amazon found a connection between the axios attacker and a domain that was involved in the typo-crypto compromise, where a malicious file disguised as the legitimate core-js package (core.js) executed upon receiving a hash input, downloading a second-stage payload from a remote server tailored to the victim’s operating system (Windows, macOS or Linux).“Based on the limited number of observed downloads, Amazon Threat Intelligence assesses that this campaign was small scale and likely served as a testing ground for the more visible supply chain operations that followed in late 2025 and 2026,” Moses wrote. “The group appears to have been refining supply chain techniques more than a year before the larger campaigns that drew public attention.”The axios attack had previously been attributed to the North Korean cluster UNC1069, which is known to overlap with Sapphire Sleet/Bluenoroff, according to a Google Cloud report on its activity. Amazon further linked this actor to the chalk and debug attacks through its analysis of C2 indicators and TTPs, which included the use of trojanized NPM packages and post-install hooks as well as reused code. These attacks had not previously been attributed to the same DPRK-sponsored threat actor as the axios attack, according to Amazon.“Defenders should not concern themselves too much with who is performing an attack and more with knowing likely techniques of a specific attacker. Distinguishing between one group and another can be helpful for defense teams, knowing whether it is North Korea or Canada is less relevant,” said Cris Thomas, security advocate at Semgrep, in comments to SC Media. “As always, defenders should rely on defense in depth, if one defense doesn’t find them another one will. The goal isn’t to prevent successful attacks but to identify limit, block and correct attacks as soon as possible.”
Threat Management, Threat Intelligence
Amazon attributes axios, debug, chalk NPM attacks to DPRK’s Sapphire Sleet

Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



