CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

A little-known npm package was North Korea’s warm-up act for the axios hack

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3483

As cited

Copy frozen at (site build).

threat intel

A little-known npm package was North Korea’s warm-up act for the axios hack

Amazon's security researchers disclosed that a North Korean hacking group (tracked as UNC1069, Sapphire Sleet, and Stardust Chollima) compromised four npm packages over eighteen months: typo-crypto in March 2025, debug and chalk in September 2025, and axios in 2026. The group gained access by building relationships with package maintainers and earned their trust to publish malicious updates, starting with lesser-known packages as practice runs before targeting widely-used libraries like axios, which sees over 100 million downloads weekly.

Why it matters: Software developers and organizations using axios, debug, chalk, or typo-crypto must audit their systems for potential compromise; the attack demonstrates that supply chain threats now spread from compromise to exploitation in hours rather than days, requiring immediate patching and runtime detection across production environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

A little-known npm package was North Korea’s warm-up act for the axios hack

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

A little-known npm package was North Korea’s warm-up act for the axios hack

Amazon security researchers noted a North Korea‑linked group that injected malicious code into the npm package typo‑crypto in March 2025, using a trusted maintainer to publish a tainted update. The same group later compromised the widely used axios, debug, and chalk packages, employing similar tactics to deliver OS‑specific second‑stage payloads. Researchers said the typo‑crypto incident served as a rehearsal that allowed the attackers to refine their approach before targeting larger libraries.

Why it matters: Developers and organizations that use npm packages such as axios, debug, and chalk should audit their dependencies for unexpected updates and enforce strict maintainer verification to prevent supply‑chain compromises.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

A little-known npm package was North Korea’s warm-up act for the axios hack

Amazon security researchers noted a North Korea‑linked group that injected malicious code into the npm package typo‑crypto in March 2025, using a trusted maintainer to publish a tainted update. The same group later compromised the widely used axios, debug, and chalk packages, employing similar tactics to deliver OS‑specific second‑stage payloads. Researchers said the typo‑crypto incident served as a rehearsal that allowed the attackers to refine their approach before targeting larger libraries.

Why it matters: Developers and organizations that use npm packages such as axios, debug, and chalk should audit their dependencies for unexpected updates and enforce strict maintainer verification to prevent supply‑chain compromises.

VendorsMicrosoftAppleAmazon Web Services
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary