CyberNotableSingle-source
5.5
Amazon attributes 2025 npm supply chain attack to North Korean threat actor Sapphire Sleet
The Hacker News·KP · US·1 day ago
Amazon threat intelligence has identified a link between a previously obscure npm package compromise and the subsequent attack on axios, attributing both to the same North Korean state-sponsored group. This discovery confirms a pattern of using smaller, initial software supply chain breaches as a testing ground for more significant operations.
Entities