Vulnerabilities

North Korea's Axios Hack Preceded by Little-Known npm Package Attacks

July 31, 2026 16:33 · 12 min read
North Korea's Axios Hack Preceded by Little-Known npm Package Attacks

Amazon's security researchers have revealed that a hacking group linked to North Korea targeted small, little-noticed software packages more than a year before it struck one of the internet's most widely used programming tools, axios.

Early Attacks on npm Packages

The company's threat intelligence team said that the same group linked to the recent compromise of the open-source axios software library also planted malicious code in a package called typo-crypto in March 2025, a full year before the axios breach. Researchers found the connection while tracing domain records tied to the axios attack back to earlier activity.

CJ Moses, Amazon's chief information security officer, stated,

We believe the March 2025 typo-crypto campaign was a rehearsal
, adding that the target's small scale let the group test its methods
without putting that on the big stage
.

Compromised Packages

Amazon said the group also compromised two other packages, debug and chalk, in September 2025. Until now, those three incidents had not been publicly linked to the same actor. Security researchers track the group under several names, including UNC1069, Sapphire Sleet, and Stardust Chollima.

Axios, debug, and chalk are code libraries used by software developers around the world to build applications. Axios alone is downloaded more than 100 million times a week, with Moses noting that

That number represents real organizations putting real code into production systems every single week
.

Malicious Code and Tactics

In the typo-crypto case, the malicious file was named core.js and was made to look like a legitimate, unrelated package called core-js. Amazon said the file activated only when it received a specific numeric input, then reached out to a server controlled by the attackers to download a second piece of code.

The code combined encoded text with a cipher, a method Moses said was meant to slow down analysis, including by AI-based review tools, without relying on heavy encryption. Amazon said the typo-crypto package had few downloads compared with axios, debug, or chalk.

Refining Tactics and Earning Trust

Researchers believe that initial target served as practice, letting the group refine its approach before turning to more widely used software. Moses noted that

They did what a lot of people do: crawl, walk, run
. In each of the four cases, Amazon said, the attackers built a relationship with a maintainer who already had access to a package, then used that access to publish an update containing hidden code.

Moses stated,

They didn’t break through a window
,
They basically earned the trust of an employee to hand them the keys
. Cybersecurity firm Wiz separately found that about 1 in 10 cloud computing environments were affected by the debug and chalk incident within a two-hour span.

Emerging Threats and Tactics

Rick Anthony, senior engineering manager at Amazon Web Services, said the research further shows how attackers face two basic problems in these types of incidents: getting malicious code into a package that will eventually run inside an organization, and keeping that code hidden from developers or security tools.

Anthony noted that groups are increasingly building reputations as legitimate contributors over time, with the mindset of

Let me get my package deployed in as many places as possible so that I can spring the trap later
. Researchers said generative AI has made it easier for attackers to produce code, documentation, and contribution histories that look authentic.

Anthony also described a technique in which attackers register package names that AI coding tools sometimes generate by mistake, so a developer following an AI suggestion could install malicious software without making any typing error of their own.

Conclusion and Wider Implications

The findings come two years after a separate incident involving a program called xz-utils, in which an attacker spent time gaining the trust of the software's maintainers before inserting a backdoor. Moses pointed to that case as an early example of a pattern now appearing

at scale
and tied to a nation-state.

Since that incident, separate groups have been running roughshod over open-source software. Another group known as TeamPCP has compromised and injected malicious code into more than 1,000 software packages over a four-month span this year.


Source: CyberScoop

Source: CyberScoop

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free