💻
Amazon links North Korean hackers to wave of NPM supply chain attacks
💻 Technology

Amazon links North Korean hackers to wave of NPM supply chain attacks

Amazon Threat Intelligence has linked a North Korean hacking group — tracked as SAPPHIRE SLEET, BlueNoroff and several other aliases — to recent compromises of widely used NPM packages including axios, debug, chalk and typo-crypto. Attackers manipulated trusted maintainers to distribute trojanized software updates to developers. Amazon warns that generative AI is enabling more convincing malware hidden inside legitimate packages.

Comments

No comments yet