Amazon: Amazon links North Korean hackers to major software attacks as generative AI makes dangerous malware increasingly difficult to detect everywhere

Amazon: Amazon links North Korean hackers to major software attacks as generative AI makes dangerous malware increasingly difficult to detect everywhere

North Korean Hacking Group Linked to Multiple NPM Supply Chain Attacks

Amazon’s Threat Intelligence team has attributed a series of high-profile software supply chain compromises to a single North Korean threat actor, tracked under aliases including SAPPHIRE SLEET, STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, and Alluring Pisces.

Between March 2025 and March 2026, the group targeted widely used NPM packages, including axios, debug, chalk, and typo-crypto, by socially engineering trusted maintainers to distribute trojanized updates. The axios package alone sees over 100 million weekly downloads, making it one of the most critical JavaScript libraries in use. Organizations that automatically pulled these updates unknowingly executed the malicious code.

During the debug and chalk compromise in September 2025, Wiz Research found that 1 in 10 cloud environments were affected within two hours. Amazon assesses the attacks as financially motivated, leveraging the efficiency of breaching a few high-impact packages to infiltrate thousands of downstream systems.

The group has evolved its tactics, shifting from single malicious packages to fragmented workflows spread across multiple seemingly benign dependencies. Attackers now exploit generative AI to craft convincing code, documentation, and maintainer identities, making detection harder. Techniques include slopsquatting registering package names hallucinated by AI coding assistants and embedding hidden instructions in comments or README files to bypass automated AI reviewers.

Amazon warns that traditional signature-based detection is becoming less effective, as attackers mutate code to evade static analysis. The company has expanded its Amazon Inspector capabilities and contributed $12.5 million to the Linux Foundation’s Akrites initiative to bolster open-source security against AI-driven threats. The shift toward AI-generated malware suggests future ransomware campaigns may adopt similar techniques.

Source: https://www.techradar.com/pro/security/amazon-flags-a-north-korean-hacker-group-as-being-behind-the-surge-in-open-source-supply-chain-attacks

Amazon Science cybersecurity rating report: https://www.rankiteo.com/company/amazonscience

"id": "AMA1785795839",
"linkid": "amazonscience",
"type": "Cyber Attack",
"date": "3/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '1 in 10 cloud environments '
                                              '(during debug and chalk '
                                              'compromise)',
                        'industry': 'Technology/Software Development',
                        'location': 'Global',
                        'name': 'NPM Packages (axios, debug, chalk, '
                                'typo-crypto)',
                        'type': 'Open-Source Software'}],
 'attack_vector': ['Social Engineering',
                   'Trojanized Package Updates',
                   'AI-Generated Malware'],
 'description': 'Amazon’s Threat Intelligence team has attributed a series of '
                'high-profile software supply chain compromises to a single '
                'North Korean threat actor, tracked under aliases including '
                'SAPPHIRE SLEET, STARDUST CHOLLIMA, BlueNoroff, '
                'CageyChameleon, and Alluring Pisces. Between March 2025 and '
                'March 2026, the group targeted widely used NPM packages, '
                'including axios, debug, chalk, and typo-crypto, by socially '
                'engineering trusted maintainers to distribute trojanized '
                'updates. The axios package alone sees over 100 million weekly '
                'downloads. Organizations that automatically pulled these '
                'updates unknowingly executed the malicious code. The group '
                'has evolved its tactics, shifting from single malicious '
                'packages to fragmented workflows spread across multiple '
                'seemingly benign dependencies, using generative AI to craft '
                'convincing code and maintainer identities.',
 'impact': {'operational_impact': 'Infiltration of cloud environments and '
                                  'downstream systems',
            'systems_affected': 'Thousands of downstream systems'},
 'initial_access_broker': {'entry_point': 'Socially engineered maintainers of '
                                          'NPM packages',
                           'high_value_targets': 'High-impact NPM packages '
                                                 '(e.g., axios, debug, chalk)'},
 'lessons_learned': 'Traditional signature-based detection is becoming less '
                    'effective against AI-driven threats. Attackers are using '
                    'generative AI to craft convincing code and maintainer '
                    'identities, making detection harder. Supply chain attacks '
                    'via high-impact packages can infiltrate thousands of '
                    'downstream systems efficiently.',
 'motivation': 'Financial',
 'post_incident_analysis': {'corrective_actions': ['Expansion of Amazon '
                                                   'Inspector capabilities',
                                                   '$12.5 million contribution '
                                                   'to Linux Foundation’s '
                                                   'Akrites initiative'],
                            'root_causes': ['Supply chain compromise via '
                                            'trojanized NPM packages',
                                            'Use of generative AI to evade '
                                            'detection',
                                            'Social engineering of '
                                            'maintainers']},
 'recommendations': 'Bolster open-source security against AI-driven threats. '
                    'Expand capabilities like Amazon Inspector. Contribute to '
                    'initiatives like the Linux Foundation’s Akrites '
                    'initiative. Adopt advanced detection methods beyond '
                    'static analysis.',
 'references': [{'source': 'Amazon Threat Intelligence Team'},
                {'source': 'Wiz Research'}],
 'response': {'enhanced_monitoring': 'Amazon Inspector capabilities expanded',
              'third_party_assistance': 'Wiz Research'},
 'threat_actor': ['SAPPHIRE SLEET',
                  'STARDUST CHOLLIMA',
                  'BlueNoroff',
                  'CageyChameleon',
                  'Alluring Pisces'],
 'title': 'North Korean Hacking Group Linked to Multiple NPM Supply Chain '
          'Attacks',
 'type': 'Supply Chain Attack',
 'vulnerability_exploited': 'Supply chain compromise via NPM packages'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.