#sapphireSleet
"ORO Hack Post-Mortem: The Sapphire Sleet Intrusion" published by ORO. #Cryptocurrency, #Phishing, #SapphireSleet, #ORO https://x.com/oroagents/status/2079371018880041257
ORO Hack Post-Mortem: The Sapphire Sleet Intrusion
x.com
July 22, 2026 at 11:19 AM
📰 Amazon Kaitkan Serangan Supply Chain npm dengan Hacker Korea Utara

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/08/03/amazon-supply-chain-npm-korea-utara/

#ama
zo#amazona#keamananSibera#koreaUtara.#nodepm ##npmS#openSourceh#sapphireSleetl#supplyChainAttack
August 3, 2026 at 8:29 AM
"Amazon identifies North Korean hacker group behind open-source supply chain attacks" published by Amazon. #SupplyChain, #NPM, #SapphireSleet, #Axios https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks
Amazon identifies North Korean hacker group behind open-source supply chain attacks
aws.amazon.com
July 30, 2026 at 12:04 AM
"From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet" published by Microsoft. #Mastra, #NPM, #SapphireSleet, #DPRK, #CTI https://www.microsoft.com/en-us/security/blog/2026/06/17/postinstall-payload-inside-mastra-npm-supply-chain-compromise/
June 20, 2026 at 3:30 AM
📢 Amazon attribue plusieurs compromissions NPM (axios, debug, chalk) au groupe nord-coréen SAPPHIRE SLEET

Cet article présente les conclusions de l'Amazon Threat Intelligence sur une série d'attaques de supply chain open source…

🟢 vérification factuelle haute
#NPM #SAPPHIRESLEET #Cyberveille
Amazon attribue plusieurs compromissions NPM (axios, debug, chalk) au groupe nord-coréen SAPPHIRE SLEET
Cet article présente les conclusions de l'Amazon Threat Intelligence sur une série d'attaques de supply chain open source attribuées à un acteur lié à la Corée du Nord (DPRK).
cyberveille.ch
August 2, 2026 at 8:30 PM
North Korean hackers poisoned Rust crates like arrayref, internment, and append-only-vec with a fake proc-macro2 dependency hiding malicious build.rs code, linking the supply chain attack to Sapphire Sleet. #Rust #SapphireSleet #NorthKorea
Rust Supply Chain Attack Linked to North Korean Hackers
North Korean hackers conducted a supply chain attack against the Rust ecosystem by poisoning the popular arrayref crate and related packages on crates.io. Wiz linked the operation to Sapphire Sleet, noting infrastructure overlaps with earlier Axios and Mastra NPM campaigns and a malicious dependency impersonating proc-macro2. #SapphireSleet #arrayref #proc-macro2 #crates.io...
www.hendryadrian.com
August 21, 2026 at 2:45 PM
DPRK Sapphire Sleet hijacked Rust crate arrayref with a typosquat compile-time backdoor. https://intel.threadlinqs.com/threat/TL-2026-2086 #ThreatIntel #systemd #arrayref #SapphireSleet
August 20, 2026 at 10:51 PM
"Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns" published by Wiz. #SapphireSleet, #UNC1069, #arrayref https://www.wiz.io/blog/rust-supply-chain-attack-on-arrayref-significant-overlap-with-dprk-campaigns
Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns
www.wiz.io
August 21, 2026 at 12:22 AM
Amazon said North Korean hacker group SapphireSleet was behind several high-profile compromises of open-source software libraries used by developers worldwide.

@therecordmedia.bsky.social

#cybersecurity
July 31, 2026 at 7:22 AM
In a report released on Wednesday, Amazon said the threat actor known as SapphireSleet was responsible for four separate compromises of popular JavaScript packages hosted on the Node Package Manager (NPM) repository.
July 31, 2026 at 7:22 AM
Amazon Attributes Earlier npm Supply Chain Attacks to North Korea's Sapphire Sleet #Amazon #malware #SapphireSleet
Amazon Attributes Earlier npm Supply Chain Attacks to North Korea's Sapphire Sleet
  Amazon has linked a series of high-profile npm supply chain compromises spanning 2025 and 2026 to the North Korean threat group Sapphire Sleet, suggesting that attacks initially viewed as isolated incidents may instead represent a coordinated campaign targeting widely trusted open source software. In a threat intelligence report published on July 29, Amazon assessed with medium confidence that the same actor responsible for the March 2026 compromise of the popular JavaScript package axios was also behind earlier attacks involving the npm packages debug and chalk, as well as a lesser-known package called typo-crypto. The assessment expands the scope of what security researchers now believe to be a sustained operation aimed at infiltrating software supply chains through compromised maintainer accounts. The September 2025 incident involving debug and chalk drew widespread attention after attackers successfully phished an npm maintainer using a fraudulent npm website designed to harvest credentials. Once access was obtained, malicious updates were published to multiple packages collectively downloaded billions of times each week. Rather than infecting developers' systems directly, the malicious code targeted cryptocurrency users by intercepting browser-based wallet activity and replacing legitimate transaction addresses before users approved transfers. At the time, security firms including Aikido Security and Wiz documented the compromise and analyzed its technical behavior, but neither publicly attributed the operation to a specific threat actor. Amazon's latest research represents the first detailed effort to connect that incident with a broader campaign linked to North Korea. According to Amazon, investigators uncovered additional evidence while examining the March 2026 axios compromise. During that investigation, analysts identified a domain registered in 2025 that ultimately led them to a previously overlooked npm package named typo-crypto. Although the package attracted relatively few downloads, Amazon believes it served as an early testing ground for techniques that later appeared in attacks targeting far more widely used libraries. The company argues that the campaigns share several operational characteristics, including the deployment of trojanized packages, overlapping command-and-control infrastructure, similarities in malicious code, and the use of social engineering to gain access to trusted maintainer accounts before distributing compromised package updates. Based on those shared indicators, Amazon believes the incidents form part of the same long-running operation. However, the report has also prompted discussion within the security community regarding the strength of the evidence supporting the attribution. While Amazon outlines common tactics and infrastructure across the campaigns, the report does not publicly specify which individual indicators directly connect each incident. As a result, some researchers have noted that although the overall assessment appears plausible, additional technical evidence would help strengthen the case for linking every campaign to the same actor. The technical methods employed across the attacks also differed substantially. The malicious code inserted into debug and chalk functioned primarily within web browsers. It intercepted browser APIs associated with cryptocurrency wallets and modified transaction destinations before users authorized transfers. Security researchers observed that the attack did not rely on npm lifecycle scripts or establish persistent malware on infected systems. By contrast, the March 2026 axios compromise involved a post-install payload that executed during package installation, allowing attackers to deploy additional malicious components. Amazon also identified similarities between that campaign and the earlier typo-crypto package, which contained a disguised file named core.js. The file reportedly activated only after receiving a specific trigger and then retrieved an operating system-specific second-stage payload from a remote command-and-control server. Amazon identified infrastructure associated with the malicious package, including the domain npmjs.store and the IP address 216.74.123.126. The company also noted that the malware concealed portions of its functionality using Base64 encoding combined with an XOR-based obfuscation routine. Further examination of the npm registry revealed additional irregularities surrounding typo-crypto. The package appeared to have been published only once, with no earlier legitimate versions preceding the malicious release. Its metadata closely resembled that of the legitimate crypto-js project, including copied descriptions and keywords, while advertising a version number ahead of crypto-js itself. Those characteristics suggest the package was created from the outset to impersonate an established library rather than resulting from the compromise of an existing maintainer account. Amazon also referenced the Open Source Vulnerabilities database entry MAL-2026-3400 in connection with typo-crypto. Registry records indicate that the package remained publicly available at the time researchers reviewed it. Although it did not declare an install script capable of automatically executing malicious code upon installation, investigators confirmed that the embedded core.js file contained trigger values consistent with Amazon's analysis. Researchers also identified discrepancies involving one published SHA-256 hash, leaving open the possibility of either a documentation error or a hash corresponding to a different sample. The attribution aligns with assessments previously made by other major cybersecurity vendors regarding the axios compromise. Google attributed that incident to the cluster it tracks as UNC1069, citing malware known as WAVESHAPER.V2 together with infrastructure previously associated with the group. Microsoft separately attributed the operation to Sapphire Sleet, a financially motivated North Korean threat actor also tracked under several alternative names by different security vendors. Threat intelligence researchers generally consider medium-confidence assessments to indicate that multiple independent indicators support an attribution while acknowledging that additional evidence could alter future conclusions. In this case, Amazon's analysis represents another step toward understanding the relationship between several supply chain attacks, even as researchers continue examining the technical links connecting them. Open source software ecosystems remain attractive targets because compromising a single trusted package can affect thousands of downstream applications and organizations. Libraries such as debug, chalk, and axios are deeply embedded throughout the JavaScript ecosystem, meaning malicious updates have the potential to propagate rapidly across development environments before they are detected. The incidents have also renewed attention on software supply chain security. Earlier this month, npm introduced version 12, disabling dependency lifecycle scripts by default to reduce opportunities for post-install malware execution. The registry has also begun scanning newly published packages for malicious code before they become available to users. While these measures help address certain attack techniques, security researchers caution that they do not eliminate the risk posed by compromised maintainer accounts obtained through phishing or other forms of social engineering. As open source ecosystems continue to expand, security experts expect attackers to increasingly focus on trusted maintainers rather than exploiting software vulnerabilities alone. The latest attribution from Amazon underlines the growing role of identity-based attacks in software supply chain operations and emphasises the continuing need for stronger maintainer protections alongside technical safeguards.
dlvr.it
July 30, 2026 at 3:38 PM
北朝鮮のハッカー集団、オープンソースのサプライチェーンを狙った大規模攻撃の背後にいたとAmazonが指摘

世界中の開発者が利用しているオープンソースソフトウェアライブラリで発生した複数の大規模な侵害事件の背後に、北朝鮮とつながりのあるハッカー集団がいたことが研究者らの調査で明らかになりました。 Amazonは水曜日に公開した報告書の中で、SapphireSleetとして知られる脅威アクターが、Node Package
北朝鮮のハッカー集団、オープンソースのサプライチェーンを狙った大規模攻撃の背後にいたとAmazonが指摘
世界中の開発者が利用しているオープンソースソフトウェアライブラリで発生した複数の大規模な侵害事件の背後に、北朝鮮とつながりのあるハッカー集団がいたことが研究者らの調査で明らかになりました。 Amazonは水曜日に公開した報告書の中で、SapphireSleetとして知られる脅威アクターが、Node Package
blackhatnews.tokyo
July 30, 2026 at 1:08 PM
North Korea phished an npm maintainer - axios itself shipped a cross-platform RAT. https://intel.threadlinqs.com/threat/TL-2026-1760 #ThreatIntel #WAVESHAPER #SILKBELL #SapphireSleet
July 29, 2026 at 9:52 PM
Amazon researchers say a North Korea-linked group used tiny typo-crypto as a rehearsal before compromising axios and other open-source packages, using trusted maintainer access and hidden code. #NorthKorea #axios #typo-crypto
A little-known npm package was North Korea’s warm-up act for the axios hack
Amazon researchers say a North Korea-linked hacking group used the tiny typo-crypto package as a rehearsal before later compromising the widely used axios library and other open-source packages. The campaign relied on trusted maintainer access, hidden malicious code, and tactics that increasingly leverage AI to blend in with legitimate development activity. #UNC1069 #SapphireSleet #StardustChollima #axios #typo-crypto #debug #chalk #xz-utils #TeamPCP
www.hendryadrian.com
July 30, 2026 at 1:15 AM
UNC1069 trasforma Axios in un vettore di spionaggio: WAVESHAPER.V2 colpisce la supply chain npm
il blog: insicurezzadigitale.com/unc1069-tras...

#cybersecurity #apt #coreadelnord #cybercrime #npm #sapphiresleet #supplychain #unc1069 #waveshaper
April 12, 2026 at 10:00 AM
Microsoft says the Mastra AI npm supply chain attack that poisoned 140+ packages was linked to North Korea’s Sapphire Sleet. Malicious updates delivered easy-day-js and a stealer for credentials, API keys, and crypto wallets. #NorthKorea #MastraAI
Microsoft links Mastra AI supply chain attack to North Korean hackers
Microsoft says the Mastra AI supply chain attack that hit more than 140 npm packages was carried out by Sapphire Sleet, also known as BlueNoroff, a North Korean state actor. The compromised packages delivered the easy-day-js dependency and a cross-platform stealer aimed at credentials, API keys, and cryptocurrency wallets. #SapphireSleet #BlueNoroff #Mastra #easy-day-js #dayjs #Axios
www.hendryadrian.com
June 20, 2026 at 5:45 PM
Malicious Axios npm releases 1.14.1 & 0.30.4 injected plain-crypto-js@4.2.1, triggering a post-install hook to download RAT payloads from a C2 server. Safe versions: 1.14.0 or 0.30.3. #SupplyChain #NodeJS #USA
Mitigating the Axios npm supply chain compromise
Two malicious Axios npm releases (axios@1.14.1 and axios@0.30.4) injected a runtime dependency plain-crypto-js@4.2.1 that executed a post-install hook to download OS-specific RAT payloads from a Sapphire Sleet-controlled C2 (hxxp://sfrclak[.]com:8000/6202033). Users of affected versions should immediately rotate credentials, downgrade to safe Axios versions (1.14.0 or 0.30.3), disable auto-updates, and follow the provided mitigations. #SapphireSleet #Axios
www.hendryadrian.com
April 2, 2026 at 7:20 AM
Sapphire Sleet targets macOS users with fake updates to steal passwords and crypto data. Stay alert. #CyberSecurity #macOS #SapphireSleet #Phishing #CryptoSecurity #InfoStealer thedailytechfeed.com/hackers-expl...
June 17, 2026 at 4:57 PM
"Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign" published by Levelblue. #SapphireSleet, #macOS, #DPRK, #CTI https://www.levelblue.com/blogs/spiderlabs-blog/sapphire-sleet-targets-macos-in-multi-stage-intrusion-campaign
May 31, 2026 at 1:30 PM
"Dissecting Sapphire Sleet’s macOS intrusion from lure to compromise" published by Microsoft. #SapphireSleet, #DPRK, #CTI https://www.microsoft.com/en-us/security/blog/2026/04/16/dissecting-sapphire-sleets-macos-intrusion-from-lure-to-compromise/
April 16, 2026 at 11:30 PM
April 1, 2026 at 11:30 PM
March 9, 2026 at 1:30 PM