UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber security

North Korea npm Supply Chain Attack: UK 2026 Audit

London · Servnet News Desk · IT infrastructure analysis4 min read
Share

Amazon has attributed the compromise of four npm packages over 18 months to a single North Korea-linked crew, Sapphire Sleet, rewriting the story from isolated incidents to a coordinated supply-chain campaign. For UK infrastructure buyers, that changes how dependency risk should be assessed and governed.

Sapphire Sleet's Alleged npm Compromise Progression
W0W13W26W39W52W65W78typo-crypto compromise20wchalk and debug compromise20wAxios compromise15wMulti-ecosystem expansion23wTotal: 78 weeks end-to-end
View the data behind this chart
Sapphire Sleet's Alleged npm Compromise Progression
PhaseStarts (week)Duration (weeks)
typo-crypto compromise020
chalk and debug compromise2020
Axios compromise4015
Multi-ecosystem expansion5523

What Amazon's research actually found

AWS published research this week attributing four separate npm package compromises — typo-crypto, chalk and debug, and Axios — to the same operation, tracked as Sapphire Sleet and widely regarded as a Lazarus Group offshoot. Amazon's confidence is described as medium, based on shared infrastructure, technical overlaps, and consistent patterns in how targets were selected and approached.

Google had already linked the Axios compromise to this group, which it tracks as UNC1069. Amazon's contribution is to argue the same operation was behind all four incidents, and that the targets grew progressively more ambitious — moving from an obscure package with few downloads towards dependencies used across millions of projects.

The attack path: people, not platforms

None of the four compromises involved exploiting npm's infrastructure or a software zero-day. Instead, the crew allegedly built relationships with maintainers, harvested their credentials, and then published malicious updates through the maintainer's own trusted account — meaning the malicious code arrived via the exact channel developers already rely on for legitimate updates.

This matters for procurement and engineering leads alike: a compromised maintainer account looks identical to a routine release. Standard code-signing or registry-level checks won't flag it, because the publishing identity itself is legitimate. Teams that implement robust vulnerability management strategies need to extend that thinking to publisher and maintainer trust, not just package contents.

Generative AI is lowering the cost of the con

AWS CISO CJ Moses set out why this tactic is becoming more durable rather than less: "Attackers can now produce thousands of lines of coherent, idiomatic, well-commented code, complete with convincing documentation, plausible commit histories, and synthetic maintainer identities, wrapped around a backdoor."

The practical effect is that pattern-matching defences degrade. Because each malicious variant can be mutated, renamed, restructured and re-encrypted, there's no stable signature for detection tooling to lock onto. That pushes the emphasis away from purely technical scanning and towards managed detection & response capable of spotting behavioural anomalies after code is already running.

Illustration: North Korea npm Supply Chain Attack: UK 2026 Audit

This is bigger than four packages

Amazon's findings sit inside a much larger pattern. Reporting this April identified more than 1,700 malicious packages across npm, PyPI, Go, Rust and Packagist since January 2025, and earlier 2025 reporting on the related Contagious Interview campaign found 67 malicious npm packages that had already accumulated over 17,000 downloads before removal. A separate June 2025 count put the tally at 35 malicious packages from 24 accounts, with six still live and downloadable at the time of that report.

The UK's own National Cyber Security Centre, in a joint warning with the Republic of Korea, has framed this explicitly as an organisational supply-chain problem rather than an individual-developer issue, noting that DPRK-linked actors are increasingly targeting software supply-chain products worldwide and have used zero-days in third-party software to gain access. Related incidents — including a Mastra AI supply-chain compromise linked to North Korean hackers, and the Phantom Circuit campaign that hit 233 victims across two waves — show the same actors working across multiple software ecosystems, not just JavaScript.

What UK infrastructure teams should do now

The Axios compromise offers a useful lesson on timing: the malicious releases were reportedly live for only around three hours yet still delivered a remote-access trojan, showing how fast CI pipelines and automated dependency resolution can turn a brief compromise window into broad exposure. That argues for treating dependency updates as an event worth logging and reviewing, not a background process.

Concretely, UK buyers should pull an accurate software bill of materials for production systems, cross-reference it against known-compromised package names and maintainer accounts, and check whether historical typosquats or clone packages from earlier waves are still sitting in build caches or lockfiles. This connects directly to broader supply-chain hygiene covered in our further insights into supply chain security, and should feed into how organisations review their IT procurement processes for any software with open-source dependencies baked in.

Longer term, this campaign is a strong argument for adopting a Zero Trust approach to build and deployment pipelines, so that a single compromised publishing account can't automatically propagate into production. Teams should also prepare for effective incident response scenarios specifically modelled on dependency poisoning, since the entry point looks nothing like a conventional breach.

Sources
  1. 01The Register — Amazon links four poisoned npm packages to one North Korean crew · 30 July 2026
  2. 02The Hacker News — N. Korean hackers spread 1,700+ malicious packages · 1 April 2026
  3. 03The Register — Lazarus Group's supply chain attack · 29 January 2025
  4. 04The Hacker News — North Korean hackers flood npm registry · 1 July 2025
  5. 05The Hacker News — UNC1069 social engineering of Axios · 1 April 2026
  6. 06The Register — Two different attackers poisoned popular open-source tools · 11 April 2026
  7. 07The Hacker News — North Korean hackers turning to new tactics · 1 June 2026
  8. 08The Hacker News — North Korea-linked supply chain attack · 1 June 2025
  9. 09The Register — North Korea npm crypto campaign · 13 February 2025
  10. 10NCSC — UK, Republic of Korea issue warning on DPRK state-linked cyber actors attacking software supply chains · 1 January 2026
  11. 11BleepingComputer — Microsoft links Mastra AI supply-chain attack to North Korean hackers · 1 June 2026
Share
Key takeaways
  • Amazon attributes four npm package compromises over 18 months to one North Korea-linked crew, Sapphire Sleet, with medium confidence.
  • The attackers targeted trusted maintainer accounts through social engineering rather than exploiting npm infrastructure or a zero-day.
  • Generative AI is helping attackers sustain convincing fake developer personas and produce backdoored code that evades pattern-based detection.
  • UK teams should audit SBOMs, check for legacy typosquats still live in lockfiles, and treat dependency-update pipelines as a Zero Trust boundary.
Frequently asked

FAQs — North Korea npm Supply Chain Attack

Who is Sapphire Sleet?

Sapphire Sleet is a North Korea-linked hacking group, widely regarded as a Lazarus Group offshoot, previously associated with cryptocurrency theft, fake job offers and long-running social engineering campaigns aimed at developers. Google tracks the same group as UNC1069.

Which npm packages were affected?

Amazon's research ties four compromises to the same operation: typo-crypto, chalk and debug, and Axios, spanning roughly 18 months and progressing from obscure packages to widely used dependencies.

Did the attackers exploit a vulnerability in npm itself?

No. According to the research, the group compromised maintainer credentials through social engineering and published malicious updates through the maintainers' own trusted accounts, rather than exploiting npm's platform or a software zero-day.

How should UK organisations respond?

Start by auditing your software bill of materials against known-compromised package and maintainer names, then implement robust vulnerability management strategies and review build-pipeline trust boundaries as part of a wider move to zero trust architecture.

Related

Turning this into a buying decision?

One conversation with an engineer who's specced this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111