Amazon researchers have connected four malicious npm packages to the Sapphire Sleet threat actor, a group linked to North Korea. The attackers used social engineering to compromise maintainer accounts and distribute malicious updates. This incident highlights the risk of supply chain compromises through trusted developer identities.
- Sapphire Sleet compromised npm packages via social engineering of maintainers
- Malicious updates were distributed through trusted developer accounts
- Amazon links this activity to a North Korean state-sponsored crew
- Monitor npm dependencies for unexpected maintainer account changes
- Audit CI/CD pipelines for unauthorized package publication events