Amazon reveals North Korean hacker group attack on NPM packages
Amazon has identified a North Korean hacker group responsible for a series of attacks on the software open source supply chain, compromising NPM packages widely used in JavaScript and Node.js application development. The compromises, also reported by the National Cybersecurity Agency (CSIRT Italia), highlight a sophisticated approach that exploits both social engineering and artificial intelligence.
Amazon Threat Intelligence Revelations
According to Amazon Threat Intelligence analysis, the compromises of the Axios, debug, and chalk packages would be attributable to the same North Korean state actor. This group, known in the cybersecurity community by various code names such as Sapphire Sleet, Stardust Chollima, BlueNoroff, CageyChameleon, and Alluring Pisces, has adopted advanced techniques to evade security systems.
The attack on Axios and the use of WAVESHAPER.V2
On March 31, 2026, the Google Threat Intelligence Group (GTIG) detected the insertion of a malicious dependency in two versions of the Axios package. This dependency installed a backdoor called WAVESHAPER.V2, a remote access trojan capable of operating on multiple operating systems, encrypting communications with the attacker's command and control center, and erasing its own traces after execution.
Social engineering and artificial intelligence
Amazon discovered that the attackers used social engineering techniques to gain the trust of package administrators and obtain the privileges necessary to publish compromised versions. Additionally, they leveraged artificial intelligence tools to refine their techniques, making the malicious code harder to detect.
CSIRT Italia Alert
CSIRT Italia issued two bulletins, one in March 2026 for the attack on Axios and another in September 2025 for the compromise of debug and chalk. Both bulletins recommended that Italian organizations verify their dependencies and update to secure versions of the packages.
The attack on debug and chalk
The second CSIRT Italia bulletin revealed that an NPM package maintainer, identified by the pseudonym Qix, was tricked by a phishing email imitating an official NPM registry communication. After providing their credentials and two-factor authentication code, the attacker published modified versions of numerous widely used packages.
Implications for open source software security
The attacks demonstrate that the weak point exploited by the attackers was not an error in the package code, but the trust placed in those who manage them. This detail often recurs in open source software security, an ecosystem built on the work of a few people on which thousands of companies depend.
By targeting a small number of very widespread packages, a group can potentially gain access to thousands of computing environments at once, a more efficient approach than targeting organizations one by one.
Technique evolution and new threats
According to Amazon Threat Intelligence, the most recent evolutions of the technique reveal a threat that no longer derives from individual compromised packages, but from the chained action triggered by the installation of multiple packages that act in a complementary manner on infected systems. This strategy prevents individual packages from being detected by security systems.
Amazon also reported a new emerging technique related to artificial intelligence, called slopsquatting, which consists of registering non-existent package names but mistakenly suggested by an AI assistant, in the hope that some developer will download them by mistake.
Response and security initiatives
Amazon shared the indicators identified with the international Open Source Vulnerabilities database and disseminated the information through its own threat detection service. Additionally, the company participated, along with the Linux Foundation, in the Akrites initiative, created to defend critical open source software from threats enabled by artificial intelligence.
CSIRT Italia continued to publish alerts on the same dependency chain, reporting multi-stage CI/CD supply chain attacks, compromises of SAP Cloud Application Programming Model components, and worm campaigns like Mini Shai-Hulud.
The emerging picture is one of a structural threat to the ecosystem of dependencies on which a large part of Italian software development rests. This exposure comes as the regulatory framework makes supply chain security an explicit obligation, underscoring the importance of adopting preventive measures to protect the open source ecosystem.
Recommendations for developers
- Verify the dependencies of your projects and update to secure versions of the packages.
- Block dependency versions using package-lock.json or yarn.lock.
- Implement advanced security controls for maintainer accounts.
- Use advanced monitoring tools to detect suspicious activity related to development accounts and code repositories.
The situation requires an immediate and coordinated approach. Italian companies must recognize the seriousness of the threat and invest in the capabilities needed to address it. The open source ecosystem is too important for Italy's digital economy to be left undefended against these sophisticated and evolving threats.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not provide real-time information.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the improper use of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves independently before making any decision.