# North Korea's npm Long Game: How Sapphire Sleet Went From Test Package to 100 Million Downloads
When the axios compromise hit in March 2026, most coverage treated it as a discrete incident — a beloved npm package backdoored, attribution to North Korean actors, patch and move on. Amazon's new analysis obliterates that framing. axios wasn't an attack. It was the third act of a campaign that began in March 2025, ran on a deliberate escalation schedule, and affected an estimated 10% of cloud environments within two hours of a single malicious update to debug and chalk.
That's not a hack. That's supply-chain infrastructure.
## The Test, The Strike, The Crown Jewel
Amazon's threat intelligence team traced the activity to Sapphire Sleet — the group also known as BlueNoroff and Stardust Chollima, a Lazarus-adjacent cluster with a long history of targeting financial institutions and crypto exchanges. The timeline they've reconstructed should make every engineering org uncomfortable.
March 2025: The group trojans typo-crypto, a small, low-visibility package. Amazon characterizes this phase as a testing ground — probing detection capabilities, refining the delivery mechanism, watching to see if anyone notices. They don't.
September 2025: The operators shift to debug and chalk. If you've spent any time in the Node.js ecosystem, you know these aren't niche packages. They are foundational dependencies — the kind that sit three or four layers deep in your dependency tree, pulled in by packages that pull in other packages. Within two hours of the malicious updates going live, roughly one in ten cloud environments had ingested them.
March 2026: axios. Over 100 million weekly downloads. At this point, the attackers weren't looking for a target — they were looking for surface area. The financial motivation Amazon highlights becomes obvious: compromise a package this widely deployed and you have indirect access to an enormous pool of downstream victims, many of them running production systems that handle sensitive data and credentials.
The social engineering angle ties it together. These weren't zero-days in npm's infrastructure. The attackers got in by convincing package maintainers — real people with real commit access — to hand over control, or by cultivating contributor status over months before introducing the malicious update. That patience is a signature.
## Slopsquatting and the AI Accelerant
Amazon's analysis introduces a term worth adding to your vocabulary: slopsquatting. The concept is unsettling in its simplicity. AI coding assistants hallucinate package names — they confidently recommend packages that don't exist. Attackers register those hallucinated names before anyone thinks to. Developers following AI suggestions, or autonomous coding agents spinning up environments, install the malicious package without a second look because the AI said it was the right one.
This isn't theoretical. It's operationally attractive because it scales. An attacker doesn't need to social-engineer a maintainer; they just need to monitor what LLMs recommend and register the gaps. Amazon flags this as an emerging vector, and given how rapidly AI-assisted development has been adopted across the industry, it deserves more alarm than it's currently receiving.
The broader AI angle cuts both ways. Sapphire Sleet, per Amazon's assessment, is using AI to generate convincing code, documentation, and even maintainer personas — lowering the cost of the trust-building phase that used to require significant human effort. The same tools accelerating legitimate development are accelerating sophisticated nation-state supply-chain attacks.
## What the Detection Gap Actually Looks Like
Amazon's report details several evasion techniques that collectively explain why these campaigns ran for over a year before attribution:
None of these techniques are individually novel. The combination, applied systematically over a multi-stage campaign by a well-resourced state actor, is the problem. A defender running standard SCA tooling would have passed a clean bill of health on these packages at multiple points during the compromise window.
## Attribution Confidence and Why It Matters
Amazon pegs its Sapphire Sleet attribution at medium confidence, based on overlapping TTPs, shared C2 infrastructure, and operational similarities across the three incidents. That's an honest and useful disclosure — "medium confidence" from a cloud provider with the telemetry footprint Amazon has is worth more than "high confidence" from a vendor with visibility into a subset of endpoints.
The practical implication: this is almost certainly coordinated state-sponsored activity with financial motivation, not opportunistic crime. That changes the threat model. A criminal crew pivots when a campaign gets burned. A nation-state actor with institutional backing and a mandate to generate hard currency has no reason to stop.
---
## HackWire Analysis
Amazon's report is valuable, but the most important thing it reveals isn't in the attribution section — it's the timeline. Fifteen months from the initial test package to the axios compromise. That's not a campaign; that's a program, running on a development schedule with defined phases and escalating objectives.
The security industry has spent years building detection capability around endpoint behavior and network anomalies. Supply-chain attacks of this design intentionally bypass both. The malicious code arrives via a trusted update mechanism, signed and distributed by the official registry. By the time behavioral detection would flag anything, the payload has already executed in thousands of environments. The debug/chalk two-hour propagation figure isn't a failure of response — it's the physics of how package ecosystems distribute updates.
What's consistently missing from coverage of incidents like this is an honest accounting of what package consumers can actually do. Dependency pinning helps but creates its own operational debt and misses the social engineering vector entirely. SBOMs are valuable for inventory but don't detect a compromised dependency that was legitimate at time of ingestion. Monitoring for unexpected outbound connections is necessary but insufficient against decoupled payloads that call home only after meeting environment criteria.
The honest answer is that the npm ecosystem — and open-source package distribution broadly — was not designed with state-sponsored supply-chain attacks as a threat model. Amazon's $12.5M Akrites commitment and the OpenSSF collaboration are the right direction, but the fundamental tension between the frictionless distribution model that made npm's ecosystem powerful and the security controls needed to stop this class of attack has not been resolved. It may not be resolvable without changing how the ecosystem works at a structural level.
For defenders right now: prioritize visibility into your dependency graph, monitor for package version changes in CI pipelines rather than just on install, and treat any dependency update touching a high-download package as a change requiring review — not just a routine bump.
— HackWire Editorial
---
## Related Coverage