CyberNotableSingle-sourceDeveloping
5.6
North Korean threat actors linked to prior npm package compromise preceding axios hack
CyberScoop·KP · US·1 day ago
Amazon security researchers have linked the 2025 hijacking of 'debug' and 'chalk' npm packages to the North Korean state-sponsored group Sapphire Sleet. The campaign compromised at least 18 packages with over 2 billion weekly downloads to facilitate cryptocurrency wallet theft. This attribution highlights the continued use of software supply chain poisoning by North Korean actors to generate illicit revenue.
Entities