Hasty Briefsbeta

Bilingual

North Korea-linked hackers targeted major NPM packages

7 hours ago
  • Amazon Threat Intelligence linked compromises of NPM packages (axios, debug, chalk, typo-crypto) to the same DPRK-linked threat actor, SAPPHIRE SLEET/STARDUST CHOLLIMA.
  • Attackers are using fragment-level attacks splitting malicious workflows across multiple seemingly benign packages, long-horizon trust-building, decoupling behavior from packages, real cryptography, and sandbox evasion.
  • Generative AI enables attackers to create convincing malicious packages at scale and introduces slopsquatting; it also creates new defense challenges as AI-based code reviewers become attack surfaces.
  • AWS responds by sharing intelligence via OSV, updating Amazon Inspector and GuardDuty, and investing in open source security initiatives like Akrites.
  • The typo-crypto compromise in March 2025 served as a testing ground for later larger-scale attacks on debug, chalk, and axios.