Security · 1h ago
Amazon ties four malicious npm packages to North Korean group
Amazon researchers linked four poisoned npm packages to Sapphire Sleet, a North Korean threat actor. The group socially engineered maintainers to publish malicious updates through trusted accounts. The packages targeted developers in the supply chain.
Meridian48 take
The attack underscores how social engineering, not just code flaws, remains a primary vector for supply chain compromises.
Read the full reporting
Amazon links four poisoned npm packages to one North Korean crew →
The Register
npmsupply-chain-attack