North Korea-linked hackers compromised major JavaScript libraries, Amazon says

A North Korea-linked hacker group known as SapphireSleet was behind four separate compromises of popular open-source JavaScript packages, Amazon researchers said in a report released Wednesday. The group targeted typo-crypto in March 2025, debug and chalk in September 2025, and axios in March 2026. Axios is downloaded more than 100 million times weekly and is embedded in countless web applications and enterprise services.
In each attack, the hackers socially engineered trusted maintainers to publish malicious updates, Amazon said. Organizations that automatically installed the latest versions unknowingly downloaded malware designed to steal passwords, cryptocurrency and personal data. Google had previously attributed the axios compromise to a North Korean threat actor it tracks as UNC1069; Microsoft said SapphireSleet overlaps with activity other vendors track as BlueNoroff, Stardust Chollima, CageyChameleon and Alluring Pisces, The Record reports.