Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » Amazon Says North Korea-Linked Hackers Targeted Axios and Other NPM Packages

Amazon Says North Korea-Linked Hackers Targeted Axios and Other NPM Packages

By:
Last updated:July 31, 2026
Human Written
  • Amazon linked four NPM package compromises to one threat actor tied to North Korea.

  • The campaign moved from a small package to widely used software, including Axios.

  • Amazon warned that AI could help attackers look more trusted inside open-source communities.

Amazon Says North Korea-Linked Hackers Targeted Axios and Other NPM Packages

Amazon has linked several open-source software breaches to one North Korea-linked threat actor. The company says separate attacks may have formed part of one wider campaign.

According to the Wall Street Journal, Amazon connected attacks involving typo-crypto, Debug, Chalk, and Axios. The company’s threat team made the link with medium confidence. Amazon based its findings on similar harmful code found in the attacks. It also found similarities in the systems used to control the affected software.

The campaign reportedly started in March 2025. Attackers first targeted the lesser-known typo-crypto package before moving toward more popular software. The attackers later targeted Debug and Chalk, which have wider use among software developers.

The campaign eventually reached Axios, a popular JavaScript library used to move data between apps and services. According to the Wall Street Journal, Axios receives more than 100 million downloads each week. A successful attack on such a widely used package could therefore reach many more users.

Attackers Target Trust in Open-Source Software

The campaign reportedly did not focus on attacking large companies directly. Instead, attackers targeted the trust that developers place in open-source software. The attackers allegedly used social engineering to gain the trust of software maintainers.

They then introduced harmful code into legitimate software updates. The exploitation of npm packages is a growing concern. The Anthropic code leaked on npm was recently used to spread malware. Developers and organizations could receive the harmful code through normal software updates. This approach allowed attackers to use trusted software as a path toward other users.

CJ Moses, Amazon’s chief information security officer for Amazon Integrated Security, described the finding as significant. According to the Wall Street Journal, Amazon had not previously publicly linked these separate incidents to one North Korea-linked actor. Amazon’s assessment also suggests the attackers may have improved their methods during the campaign.

The activity moved from typo-crypto toward packages with much wider use. The Wall Street Journal reported that Amazon believes the campaign shows the value of attacking trusted software dependencies. One compromised package can potentially reach many users who depend on it.

Amazon’s findings come as security teams continue to watch attacks against the NPM software ecosystem. In an AWS Security Blog analysis, Amazon discussed several recent software supply-chain incidents. The analysis mentioned campaigns involving Shai-Hulud, the Chalk and Debug compromise, and the Axios attack. AWS said these incidents show why organizations should check their software dependencies carefully.

AI Could Help Attackers Look More Trustworthy

Amazon also warned that artificial intelligence could make these attacks harder to spot. According to the Wall Street Journal, researchers said attackers are using AI to appear more like real members of open-source communities. Attackers can use AI to help contribute code and fix software bugs. They can also use it to respond to requests and create documentation.

The researchers said attackers may carry out these activities over long periods. This could help them build trust before attempting to place harmful code into software packages.

The findings also show why open-source software remains an attractive target. The AWS Security Blog previously warned that attackers can target package registries because one trusted package may connect to many other systems. The latest campaign highlights the need for organizations to watch the software they use.

AWS recommends stronger controls around software dependencies and checks for package integrity and source. Organizations can also review package versions and check where their software comes from. They should protect developer login details and secure the systems used to build software.

The campaign shows how attackers can use trusted open-source software to reach a wider group of users. Amazon’s findings also point to a growing challenge for developers as AI tools become more common in software communities.

The AWS Security Blog said organizations should strengthen their software supply-chain controls. It also stressed the need to verify software packages before adding them to applications.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.