'Generative AI is already changing what malicious software packages look like and how threat actors are beginning to probe AI-based code systems': Amazon flags North Korean hacker group as being behind the surge in open source supply chain attacks

North Korean hackers quietly poisoned trusted software packages

by · TechRadar

News By Efosa Udinmwen Published 3 August 2026 2 min read

(Image credit: Shutterstock)

Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter


  • Amazon links multiple software supply chain attacks to one North Korean hacking group
  • Generative AI enables convincing malware hidden inside trusted software packages at scale
  • Attackers manipulated trusted maintainers before distributing compromised software updates to developers

Amazon has linked a North Korean threat actor to several recent compromises of popular NPM software libraries.

A report from Amazon Threat Intelligence connected recent breaches of the axios, debug, chalk, and typo-crypto packages to a single group.

That group is tracked across the security community under names including SAPPHIRE SLEET, STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, and Alluring Pisces.

Latest Videos FromTechRadarWatch full video here:

Attackers exploit trust to compromise widely used packages

In March 2025, the threat actor compromised the typo-crypto package through a trojanized file disguised as a legitimate dependency.

The same group later compromised debug and chalk in September 2025, then axios in March 2026.

Axios alone carries more than 100 million weekly downloads, making it one of the most widely used JavaScript libraries in existence today.

In each case, attackers socially engineered a trusted maintainer before publishing a malicious software update.

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Contact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsors