- Amazon Threat Intelligence linked compromises of NPM packages (axios, debug, chalk, typo-crypto) to the same DPRK-linked threat actor, SAPPHIRE SLEET/STARDUST CHOLLIMA.
- Attackers are using fragment-level attacks splitting malicious workflows across multiple seemingly benign packages, long-horizon trust-building, decoupling behavior from packages, real cryptography, and sandbox evasion.
- Generative AI enables attackers to create convincing malicious packages at scale and introduces slopsquatting; it also creates new defense challenges as AI-based code reviewers become attack surfaces.
- AWS responds by sharing intelligence via OSV, updating Amazon Inspector and GuardDuty, and investing in open source security initiatives like Akrites.
- The typo-crypto compromise in March 2025 served as a testing ground for later larger-scale attacks on debug, chalk, and axios.