Amazon identifies North Korean hacker group behind open-source supply chain attacks | AWS Security Blog
AI Summary
Amazon Threat Intelligence has identified a DPRK-linked threat actor behind multiple supply chain attacks on popular NPM packages including axios, debug, chalk, and typo-crypto. The actor used social engineering to gain access to maintainer accounts and published trojanized updates containing malicious code. These attacks leveraged post-install hooks, multi-stage payloads, and C2 infrastructure to deliver malware across thousands of downstream environments. The same actor is assessed to have tested their tradecraft in a smaller campaign via the typo-crypto package before escalating to higher-impact compromises. The group uses sophisticated evasion techniques including code obfuscation, environment detection to avoid sandboxes, and generative AI to produce convincing malicious packages.
AI-extracted · verify before operational use
Extracted Entities 3 found
Indicators of Compromise 6 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | npmjs[.]store | Details → |
| IP | 216[.]74[.]123[.]126 | Details → |
| Package | typo-crypto | Details → |
| SHA-256 | 24604384b0e748ada07923630b3d037489e696284a98c4409fb9b6763565571f | Details → |
| Filename | core.js | Details → |
| SHA-256 | 2014d09c7ded74d89c885b5f11693865224116f1b25df9330e61fe528f419d73 | Details → |