static-urls · Crawled Jul 31, 2026

Amazon identifies North Korean hacker group behind open-source supply chain attacks | AWS Security Blog

6 IoCs 2 Actors 1 Malware
Read original article ↗

AI Summary

Amazon Threat Intelligence has identified a DPRK-linked threat actor behind multiple supply chain attacks on popular NPM packages including axios, debug, chalk, and typo-crypto. The actor used social engineering to gain access to maintainer accounts and published trojanized updates containing malicious code. These attacks leveraged post-install hooks, multi-stage payloads, and C2 infrastructure to deliver malware across thousands of downstream environments. The same actor is assessed to have tested their tradecraft in a smaller campaign via the typo-crypto package before escalating to higher-impact compromises. The group uses sophisticated evasion techniques including code obfuscation, environment detection to avoid sandboxes, and generative AI to produce convincing malicious packages.

AI-extracted · verify before operational use

Extracted Entities 3 found

Indicators of Compromise 6 extracted

Type Value Detail
Domain npmjs[.]store Details →
IP 216[.]74[.]123[.]126 Details →
Package typo-crypto Details →
SHA-256 24604384b0e748ada07923630b3d037489e696284a98c4409fb9b6763565571f Details →
Filename core.js Details →
SHA-256 2014d09c7ded74d89c885b5f11693865224116f1b25df9330e61fe528f419d73 Details →

MITRE ATT&CK TTPs 17 techniques