static-urls · Crawled Jul 31, 2026

Amazon identifies North Korean hacker group behind open-source supply chain attacks | AWS Security Blog

6 IoCs 2 Actors 1 Malware
Read original article ↗

AI Summary

Amazon Threat Intelligence has identified a DPRK-linked threat actor behind multiple supply chain attacks on popular NPM packages including axios, debug, chalk, and typo-crypto. The actor used social engineering to gain access to maintainer accounts and published trojanized updates containing malicious code. These attacks leveraged post-install hooks, multi-stage payloads, and C2 infrastructure to deliver malware across thousands of downstream environments. The same actor is assessed to have tested their tradecraft in a smaller campaign via the typo-crypto package before escalating to higher-impact compromises. The group uses sophisticated evasion techniques including code obfuscation, environment detection to avoid sandboxes, and generative AI to produce convincing malicious packages.

AI-extracted · verify before operational use

Extracted Entities 3 found

Indicators of Compromise 6 extracted

Type Value Detail
Domain npmjs[.]store Details →
IP 216[.]74[.]123[.]126 Details →
Package typo-crypto Details →
SHA-256 24604384b0e748ada07923630b3d037489e696284a98c4409fb9b6763565571f Details →
Filename core.js Details →
SHA-256 2014d09c7ded74d89c885b5f11693865224116f1b25df9330e61fe528f419d73 Details →

MITRE ATT&CK TTPs 53 techniques

T1001 Data Obfuscation · Command And Control T1003 OS Credential Dumping · Credential Access T1018 Remote System Discovery · Discovery T1021.001 Remote Desktop Protocol · Lateral Movement T1021.002 SMB/Windows Admin Shares · Lateral Movement T1021.004 SSH · Lateral Movement T1021.006 Windows Remote Management · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1029 Scheduled Transfer · Exfiltration T1036.005 Match Legitimate Name or Location · Defense Evasion T1040 Network Sniffing · Credential Access T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1057 Process Discovery · Discovery T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1070.001 Clear Windows Event Logs · Defense Evasion T1070.004 File Deletion · Defense Evasion T1070.006 Timestomp · Defense Evasion T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1085 T1085 T1087 Account Discovery · Discovery T1090 Proxy · Command And Control T1098 Account Manipulation · Persistence T1105 Ingress Tool Transfer · Command And Control T1129 Shared Modules · Execution T1133 External Remote Services · Persistence T1134 Access Token Manipulation · Defense Evasion T1190 Exploit Public-Facing Application · Initial Access T1195.002 Compromise Software Supply Chain · Initial Access T1203 Exploitation for Client Execution · Execution T1204.002 Malicious File · Execution T1210 Exploitation of Remote Services · Lateral Movement T1218 System Binary Proxy Execution · Defense Evasion T1218.011 Rundll32 · Defense Evasion T1480 Execution Guardrails · Defense Evasion T1485 Data Destruction · Impact T1486 Data Encrypted for Impact · Impact T1495 Firmware Corruption · Impact T1534 Internal Spearphishing · Lateral Movement T1548 Abuse Elevation Control Mechanism · Privilege Escalation T1557 Adversary-in-the-Middle · Credential Access T1558 Steal or Forge Kerberos Tickets · Credential Access T1566 Phishing · Initial Access T1566.001 Spearphishing Attachment · Initial Access T1566.002 Spearphishing Link · Initial Access T1583 Acquire Infrastructure · Resource Development T1610 Deploy Container · Defense Evasion